Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

fission — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting fission. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents security vulnerabilities associated with the software vendor fission, specifically focusing on weaknesses classified under the Common Weakness Enumeration taxonomy. It serves as a centralized repository for tracking known flaws, configuration errors, and implementation defects that have been identified within products developed or maintained by this specific entity. The content aggregated here encompasses a wide spectrum of security issues, ranging from cross-site scripting and injection flaws to more critical privilege escalation and information disclosure defects. The data spans multiple years, covering the full lifecycle of reported vulnerabilities from their initial disclosure through to any subsequent patching or mitigation efforts. This temporal scope allows users to analyze trends in vulnerability discovery and remediation speed over time. By reviewing this collection, security professionals can track a vendor's advisories to stay informed about emerging risks in their infrastructure. It also provides the context necessary to understand a specific weakness class as it manifests within fission’s codebase or deployment architecture. Furthermore, users can look up a product's vulnerability history to assess long-term security hygiene and make informed decisions regarding procurement, integration, or risk acceptance. This resource is designed to support threat modeling and vulnerability management workflows by providing a clear, factual record of past and present security issues.

Top products by fission: fission
CVE IDTitleCVSSSeverityPublished
CVE-2026-50570 Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption — fissionCWE-269 8.5 High2026-06-10
CVE-2026-50569 Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks — fissionCWE-20 4.3 Medium2026-06-10
CVE-2026-50568 Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape — fissionCWE-41 3.6 Low2026-06-10
CVE-2026-50567 Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory — fissionCWE-22 7.7 High2026-06-10
CVE-2026-50566 Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation — fissionCWE-250 9.9 Critical2026-06-10
CVE-2026-50565 Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container — fissionCWE-250 4.9 Medium2026-06-10
CVE-2026-50564 Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape — fissionCWE-269 9.9 Critical2026-06-10
CVE-2026-50563 Fission Container Executor Function PodSpec Injection Leading to Node Escape — fissionCWE-269 9.9 Critical2026-06-10
CVE-2026-50545 Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover — fissionCWE-269 9.9 Critical2026-06-10
CVE-2026-49824 Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook — fissionCWE-284 8.5 High2026-06-10
CVE-2026-49823 Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook — fissionCWE-284 7.7 High2026-06-10
CVE-2026-49822 Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance — fissionCWE-284 7.7 High2026-06-10
CVE-2026-49821 Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration — fissionCWE-441 7.7 High2026-06-10
CVE-2026-46618 Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables — fissionCWE-78--2026-06-10
CVE-2026-46617 Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read — fissionCWE-250--2026-06-10
CVE-2026-46612 Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives — fissionCWE-306 8.8 High2026-06-10
CVE-2026-46614 Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger — fissionCWE-284 9.8 Critical2026-06-10

This page lists every published CVE security advisory associated with fission. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.