Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

fission — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in fission, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the open-source Kubernetes-native serverless platform, Fission, categorized under software application weaknesses. It compiles a comprehensive list of identified security flaws, including remote code execution, privilege escalation, and information disclosure issues that have been reported against the product. The data covers all known vulnerabilities discovered from the product's initial release up to the most recent updates, ensuring a complete historical perspective on its security posture. Here, users can track a vendor’s advisories to stay informed about critical patches and mitigation strategies released by the Fission community. Readers can also understand a specific weakness class by analyzing recurring patterns and attack vectors associated with Fission’s architecture, such as container isolation failures or API gateway misconfigurations. Additionally, one can look up a product's vulnerability history to assess the evolution of its security practices over time and evaluate the effectiveness of previous remediation efforts. This centralized view helps developers, security analysts, and DevOps engineers make informed decisions about risk management and deployment configurations. By aggregating these details, the page serves as a single source of truth for understanding the security landscape surrounding Fission. It eliminates the need to search through multiple disparate sources, providing a clear and structured overview of known issues. This approach supports proactive security hygiene and aids in prioritizing updates based on the severity and relevance of each vulnerability to specific deployment environments.

Vendor: fission

CVE IDTitleCVSSSeverityPublished
CVE-2026-50570 Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption CWE-269 8.5 High2026-06-10
CVE-2026-50569 Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks CWE-20 4.3 Medium2026-06-10
CVE-2026-50568 Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape CWE-41 3.6 Low2026-06-10
CVE-2026-50567 Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory CWE-22 7.7 High2026-06-10
CVE-2026-50566 Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation CWE-250 9.9 Critical2026-06-10
CVE-2026-50565 Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container CWE-250 4.9 Medium2026-06-10
CVE-2026-50564 Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape CWE-269 9.9 Critical2026-06-10
CVE-2026-50563 Fission Container Executor Function PodSpec Injection Leading to Node Escape CWE-269 9.9 Critical2026-06-10
CVE-2026-50545 Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover CWE-269 9.9 Critical2026-06-10
CVE-2026-49824 Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook CWE-284 8.5 High2026-06-10
CVE-2026-49823 Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook CWE-284 7.7 High2026-06-10
CVE-2026-49822 Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance CWE-284 7.7 High2026-06-10
CVE-2026-49821 Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration CWE-441 7.7 High2026-06-10
CVE-2026-46618 Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables CWE-78--2026-06-10
CVE-2026-46617 Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read CWE-250--2026-06-10
CVE-2026-46612 Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives CWE-306 8.8 High2026-06-10
CVE-2026-46614 Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger CWE-284 9.8 Critical2026-06-10

All 17 known CVE vulnerabilities affecting fission with full Chinese analysis, references, and POCs where available.