CVE Explorer
CVE-2026-50569
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeURL and Prefix. Those two fields were validated at the CLI level only (pkg/fission-cli/cmd/httptrigger/create.go:83). The post-CRD-modernization webhook for HTTPTrigger was retired in favor of API-serve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"fission","vendor":"fission","versions":[{"status":"affected","version":"< 1.25.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/fission/fission/pull/3464","tags":["x_refsource_MISC"],"url":"https://github.com/fission/fission/pull/3464"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/references/1
{"name":"https://github.com/fission/fission/releases/tag/v1.25.0","tags":["x_refsource_MISC"],"url":"https://github.com/fission/fission/releases/tag/v1.25.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/references/2
{"name":"https://github.com/fission/fission/security/advisories/GHSA-vchh-r53j-8mpw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/fission/fission/security/advisories/GHSA-vchh-r53j-8mpw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:42db2234349edc52c468acd45cfd0d0c055505584e75c04eb8caead1f9f2abd9 · sha256:64933a5afff5c3e8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.