PT-2026-48514 · Fission · Fission
CVE-2026-50569
·
Published
2026-06-10
·
Updated
2026-09-04
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fission versions prior to 1.25.0
Description
Fission is a Kubernetes-native serverless framework. A flaw exists where the
HTTPTriggerSpec.Validate() function fails to validate the RelativeURL and Prefix variables, while only validating Methods, FunctionReference, Host, IngressConfig, and CorsConfig. Because these two fields were only validated at the CLI level and the API-server CEL (Common Expression Language) lacked rules for them, any HTTPTrigger created through a direct Kubernetes REST API call or via kubectl apply bypasses all URL-level checks.Recommendations
Update to version 1.25.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fission