Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

fission — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in fission, with AI-generated Chinese analysis, references, and POCs.

This page presents a comprehensive aggregation of vulnerability data for Fission, specifically focusing on Common Weakness Enumeration (CWE) classifications and associated security tags. It collects a wide range of identified security flaws, including software bugs, configuration errors, and design vulnerabilities, covering historical records from the product's inception through the most recent updates. By accessing this resource, users can effectively track vendor advisories to stay informed about patches and mitigations, gain a deeper understanding of specific weakness classes prevalent in the Fission architecture, and examine the complete vulnerability history of the product to assess long-term security trends. This centralized view helps developers and security analysts correlate past incidents with current threat landscapes, enabling more informed decision-making regarding system hardening and risk management. The data is organized to facilitate easy navigation, allowing stakeholders to quickly identify critical issues without wading through unstructured information. Whether you are a system administrator responsible for maintaining Fission instances or a security researcher analyzing open-source project stability, this page serves as a vital reference point for understanding the security posture of the software over time. The information provided is intended to support proactive security measures and continuous improvement of application safety standards.

Vendor: fission

CVE ID Title CVSS Severity Published
CVE-2026-50570 Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption CWE-269 8.5 High 2026-06-10
CVE-2026-50569 Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks CWE-20 4.3 Medium 2026-06-10
CVE-2026-50568 Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape CWE-41 3.6 Low 2026-06-10
CVE-2026-50567 Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory CWE-22 7.7 High 2026-06-10
CVE-2026-50566 Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation CWE-250 9.9 Critical 2026-06-10
CVE-2026-50565 Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container CWE-250 4.9 Medium 2026-06-10
CVE-2026-50564 Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape CWE-269 9.9 Critical 2026-06-10
CVE-2026-50563 Fission Container Executor Function PodSpec Injection Leading to Node Escape CWE-269 9.9 Critical 2026-06-10
CVE-2026-50545 Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover CWE-269 9.9 Critical 2026-06-10
CVE-2026-49824 Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook CWE-284 8.5 High 2026-06-10
CVE-2026-49823 Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook CWE-284 7.7 High 2026-06-10
CVE-2026-49822 Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance CWE-284 7.7 High 2026-06-10
CVE-2026-49821 Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration CWE-441 7.7 High 2026-06-10
CVE-2026-46618 Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables CWE-78 - - 2026-06-10
CVE-2026-46617 Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read CWE-250 - - 2026-06-10
CVE-2026-46612 Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives CWE-306 8.8 High 2026-06-10
CVE-2026-46614 Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger CWE-284 9.8 Critical 2026-06-10

All 17 known CVE vulnerabilities affecting fission with full Chinese analysis, references, and POCs where available.