VulnSea

fission has 16 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 2 in the 90 before. The busiest recent month was June 2026 with 10. The median CVSS is 8.1 (high), with 4 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-269 (7) and CWE-284 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
14 prev 2

Products

  • github.com/fission/fission 16
16
Total CVEs
4
Critical
0
CISA KEV
0
Exploited

fission vulnerabilities

CVEs affecting fission, newest first. Open any entry for full detail, references, and exploit status.

16 CVEsRSS

CVE-2026-50570High· 8.5
1mo ago

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Twilightfission · github.com/fission/fissionEPSS 0.27%via GHSA
CVE-2026-50569Medium· 4.3
1mo ago

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Sunlitfission · github.com/fission/fissionEPSS 0.23%via GHSA
CVE-2026-50567High· 7.7
1mo ago

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Twilightfission · github.com/fission/fissionEPSS 0.30%via GHSA
CVE-2026-50568Low· 3.6
1mo ago

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Sunlitfission · github.com/fission/fissionEPSS 0.11%via GHSA
GHSA-7m8x-qg2j-4m3vHigh· 8.1
2mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-49821High· 7.7
2mo ago

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Twilightfission · github.com/fission/fissionEPSS 0.23%via GHSA
CVE-2026-49822High· 7.7
2mo ago

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Twilightfission · github.com/fission/fissionEPSS 0.23%via GHSA
CVE-2026-49823High· 7.7
2mo ago

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Twilightfission · github.com/fission/fissionEPSS 0.27%via GHSA
CVE-2026-49824High· 8.5
2mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Twilightfission · github.com/fission/fissionEPSS 0.24%via GHSA
CVE-2026-50545Critical· 9.9
2mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Midnightfission · github.com/fission/fissionEPSS 0.30%via GHSA
CVE-2026-50563Critical· 9.9
2mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Midnightfission · github.com/fission/fissionEPSS 0.27%via GHSA
CVE-2026-50564Critical· 9.9
2mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Midnightfission · github.com/fission/fissionEPSS 0.27%via GHSA
CVE-2026-50565Medium· 4.9
2mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Sunlitfission · github.com/fission/fissionEPSS 0.26%via GHSA
CVE-2026-50566Critical· 9.9
2mo ago

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Midnightfission · github.com/fission/fissionEPSS 0.29%via GHSA
CVE-2026-46612High· 8.8
4mo ago

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Twilightfission · github.com/fission/fissionEPSS 0.34%via OSV
CVE-2026-46617High
4mo ago

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code names…

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read

Twilightfission · github.com/fission/fissionEPSS 0.35%via OSV
fission vulnerabilities (CVEs) · VulnSea