PT-2026-48514 · Fission · Fission

CVE-2026-50569

·

Published

2026-06-10

·

Updated

2026-09-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fission versions prior to 1.25.0
Description Fission is a Kubernetes-native serverless framework. A flaw exists where the HTTPTriggerSpec.Validate() function fails to validate the RelativeURL and Prefix variables, while only validating Methods, FunctionReference, Host, IngressConfig, and CorsConfig. Because these two fields were only validated at the CLI level and the API-server CEL (Common Expression Language) lacked rules for them, any HTTPTrigger created through a direct Kubernetes REST API call or via kubectl apply bypasses all URL-level checks.
Recommendations Update to version 1.25.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50569
GHSA-VCHH-R53J-8MPW
GO-2026-6131
OPENSUSE-SU-2026:21761-1

Affected Products

Fission