Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
CVE-2026-49821

7.7HIGH

Key Information:

Vendor

Fission

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-49821?

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package.metadata.namespace. This issue has been patched in version 1.24.0.

Affected Version(s)

fission < 1.24.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.