github.com/fission/fission vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50566Criticalgithub.com/fission/fission: Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creationCVE-2026-50565Mediumgithub.com/fission/fission: Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerCVE-2026-50564Criticalgithub.com/fission/fission: Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escapeCVE-2026-50563Criticalgithub.com/fission/fission: Fission Container Executor Function PodSpec Injection Leading to Node EscapeCVE-2026-50545Criticalgithub.com/fission/fission: Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverCVE-2026-49824Highgithub.com/fission/fission: Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhookCVE-2026-49823Highgithub.com/fission/fission: Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhookCVE-2026-49822Highgithub.com/fission/fission: Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillanceCVE-2026-49821Highgithub.com/fission/fission: Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltrationGHSA-7M8X-QG2J-4M3VHighgithub.com/fission/fission: Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpecCVE-2026-46618Mediumgithub.com/fission/fission: Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary…CVE-2026-46617Highgithub.com/fission/fission: Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code…CVE-2026-46614Criticalgithub.com/fission/fission: Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTriggerCVE-2026-46612Highgithub.com/fission/fission: Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Stop the waste.
Protect your environment with Kodem.