CRITICAL9.9CVE-2026-50566Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation in github.com/fission/fission from 0, < 1.24.0
CRITICAL9.9CVE-2026-50566Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation in github.com/fission/fission from 0, < 1.24.0
CRITICAL9.9CVE-2026-50564Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape in github.com/fission/fission from 0, < 1.24.0
CRITICAL9.9Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape in github.com/fission/fission
from 0, < 1.24.0
CRITICAL9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape in github.com/fission/fission
from 0, < 1.24.0
CRITICAL9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape in github.com/fission/fission
from 0, < 1.24.0
CRITICAL9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover in github.com/fission/fission
from 0, < 1.24.0
CRITICAL9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover in github.com/fission/fission
from 0, < 1.24.0
CRITICAL9.8Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger in github.com/fission/fission
from 0, < 1.23.0
CRITICAL9.8Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger in github.com/fission/fission
from 0, < 1.23.0
HIGH8.8Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives in github.com/fission/fission
from 0, < 1.23.0
HIGH8.8Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives in github.com/fission/fission
from 0, < 1.23.0
HIGH8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook in github.com/fission/fission
from 0, < 1.24.0
HIGH8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration in github.com/fission/fission
from 0, < 1.24.0
HIGH7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration in github.com/fission/fission
from 0, < 1.24.0
MEDIUM4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container in github.com/fission/fission
from 0, < 1.24.0
MEDIUM4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container in github.com/fission/fission
from 0, < 1.24.0
—Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables in github.com/fission/fission
from 0, < 1.23.0
—Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables in github.com/fission/fission
from 0, < 1.23.0
—Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read in github.com/fission/fission
from 0, < 1.23.0
—Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read in github.com/fission/fission
from 0, < 1.23.0