Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-50651

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Visual Studio 2022 version 17.14, .NET 10.0, Microsoft Visual Studio 2026 version 18.7, .NET 9.0, .NET 8.0, Microsoft Visual Studio 2022 version 17.12
Provider severity
HIGH
Conflicts
1

CVE-2026-50650

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft Visual Studio 2026 version 18.7, .NET 9.0, Microsoft Visual Studio 2022 version 17.14, Microsoft .NET Framework 3.5, .NET 8.0, Microsoft .NET Framework 4.8, Microsoft Visual Studio 2022 version 17.12, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
Provider severity
HIGH
Conflicts
1

CVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

PUBLISHED
Vendor
IBM
Product
Controller
Provider severity
HIGH
Conflicts
0

CVE-2026-50649

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 8.0, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.8.1, .NET 9.0, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Microsoft Visual Studio 2026 version 18.7, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 4.8
Provider severity
HIGH
Conflicts
1

CVE-2026-50648

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 10.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft Visual Studio 2026 version 18.7, Microsoft .NET Framework 3.5, .NET 9.0, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft Visual Studio 2022 version 17.14, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 4.8, .NET 8.0, Microsoft Visual Studio 2022 version 17.12
Provider severity
HIGH
Conflicts
1

CVE-2026-50647

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Windows Server 2012 (Server Core installation), Windows Server 2025, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2012, Microsoft .NET Framework 4.8, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Microsoft .NET Framework 4.8.1, Microsoft .NET Framework 3.5 AND 4.8.1, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-50646

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 8.0, Microsoft .NET Framework 3.5 AND 4.8, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2022 version 17.12, Microsoft .NET Framework 4.8, .NET 9.0, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft Visual Studio 2026 version 18.7, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
Provider severity
HIGH
Conflicts
2

CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
HIGH
Conflicts
0

CVE-2026-50644

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01.

PUBLISHED
Vendor
SOPlanning
Product
SOPlanning
Provider severity
HIGH
Conflicts
0

CVE-2026-50643

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controlled filename and line number metadata and later uses it without validation when accessing source line arrays. By supplying invalid or oversized line numbers, an attacker can trigger out-of-bounds memory access and a crash. Maintainer of this project was notified early about this vulnerability, but didn't respond with the details of vulnerability or vu

PUBLISHED
Vendor
rui314
Product
8cc
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50642

diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escape sequences (e.g., OSC, CSI), to pass through unsanitized. An attacker can embed malicious control sequences in filenames, diff metadata, or file content that are rendered directly in the terminal during diff viewing. This can lead to output manipulation, including

PUBLISHED
Vendor
so-fancy
Product
diff-so-fancy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50641

Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.

PUBLISHED
Vendor
Streamsoft
Product
Business Intelligence
Provider severity
HIGH
Conflicts
0

CVE-2026-5064

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities.

PUBLISHED
Vendor
HP Inc.
Product
HP One Agent Software
Provider severity
HIGH
Conflicts
0

CVE-2026-50639

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections.

PUBLISHED
Vendor
PEVANS
Product
Metrics::Any::Adapter::SignalFx
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50638

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injections.

PUBLISHED
Vendor
PEVANS
Product
Metrics::Any::Adapter::DogStatsd
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50637

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and statsd control characters (colon, pipe) then metric injections are possible. Version 0.04 fixed this by modifying the _make method to block metric names with characters below ASC

PUBLISHED
Vendor
PEVANS
Product
Metrics::Any::Adapter::Statsd
Provider severity
HIGH
Conflicts
1

CVE-2026-50636

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated attacker holding the tokens/update permission on a survey can inject a crafted array element to perform SQL injection. Because LimeSurvey configures its PDO connection with emulated prepared statements (emulate

PUBLISHED
Vendor
LimeSurvey
Product
LimeSurvey
Provider severity
HIGH
Conflicts
1

CVE-2026-50635

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email

PUBLISHED
Vendor
LimeSurvey
Product
LimeSurvey
Provider severity
HIGH
Conflicts
1

CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity parsing or signed-header consistency checks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50633

A flaw was found in Apache CXF's JCA integration module. This Java Naming and Directory Interface (JNDI) Injection vulnerability allows for arbitrary code execution. A remote attacker could exploit this by manipulating the Java EE Connector Architecture (JCA) deployment descriptor (ra.xml) or runtime activation parameters, leading to the execution of malicious code on the affected system.

PUBLISHED
Vendor
Red Hat, Apache Software Foundation, Red Hat, Red Hat
Product
Red Hat Fuse 7, Apache CXF, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16
Provider severity
HIGH
Conflicts
2

CVE-2026-50632

A flaw was found in Apache CXF. This vulnerability, stemming from an incomplete fix for a previous issue, allows untrusted users who can configure Java Message Service (JMS) for Apache CXF to achieve arbitrary code execution. This could lead to a complete compromise of the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat
Product
Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Apache CXF, Red Hat JBoss Enterprise Application Platform Expansion Pack
Provider severity
HIGH
Conflicts
3

CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
HIGH
Conflicts
0

CVE-2026-50630

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5063

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
webaways
Product
NEX-Forms – Ultimate Forms Plugin for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-50629

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50628

A flaw was found in the OAuthRequestFilter component of cxf. A logic error in this filter inadvertently creates an inverse security check when enabled. This issue causes legitimate requests from a bound IP address to be rejected, while requests from any other IP address are blindly allowed. This could lead to unauthorized access to resources.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation
Product
Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Web Server 5, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Fuse 7, Red Hat JBoss Web Server 5, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Apache CXF
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Apache CXF, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Web Server 5, Red Hat Fuse 7, Red Hat JBoss Web Server 5, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Fuse 7, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-50623

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache CXF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Atlas
Provider severity
HIGH
Conflicts
0

CVE-2026-5061

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.

PUBLISHED
Vendor
HashiCorp
Product
Tooling
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5060

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumer

PUBLISHED
Vendor
stylemix
Product
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50593

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

PUBLISHED
Vendor
Graphite project
Product
Graphite
Provider severity
HIGH
Conflicts
0

CVE-2026-50592

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

PUBLISHED
Vendor
Znuny
Product
Znuny
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50591

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

PUBLISHED
Vendor
Znuny
Product
Znuny
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50590

In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

PUBLISHED
Vendor
Mimecast
Product
Incydr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5059

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to ex

PUBLISHED
Vendor
aws-mcp-server
Product
aws-mcp-server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-50589

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

PUBLISHED
Vendor
Red Hat, OpenStack, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Ironic, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-5058

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute co

PUBLISHED
Vendor
aws-mcp-server
Product
aws-mcp-server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed i

PUBLISHED
Vendor
yt-dlp
Product
yt-dlp
Provider severity
HIGH
Conflicts
0

CVE-2026-50573

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is already locked with an integrity value, and the registry later serves different metadata and tarball content for the same package name and version, pnpm initially reports an integrity mismatch. However, plain pnpm install then performs a resolution repa

PUBLISHED
Vendor
pnpm
Product
pnpm
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50570

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSafety admission webhook + sanitizeContainerSecurityContext executor merge layer), but the capability check was implemented as a fixed denylist of six Linux capabilities (SYS_ADMIN, NET_ADMIN, SYS_PTRACE

PUBLISHED
Vendor
fission
Product
fission
Provider severity
HIGH
Conflicts
1

CVE-2026-5057

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition

PUBLISHED
Vendor
ATEN
Product
Unizon
Provider severity
HIGH
Conflicts
0

CVE-2026-50569

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeURL and Prefix. Those two fields were validated at the CLI level only (pkg/fission-cli/cmd/httptrigger/create.go:83). The post-CRD-modernization webhook for HTTPTrigger was retired in favor of API-serve

PUBLISHED
Vendor
fission
Product
fission
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50568

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling strings.HasPrefix(path, safedir). This is a lexical check, not a directory boundary check: /packages-extra/evil starts with /packages, so it passed. The function did not enforce a path-separator boundary, so any sibling directory w

PUBLISHED
Vendor
fission
Product
fission
Provider severity
LOW
Conflicts
0

CVE-2026-50567

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named ../../tmp/evil therefore landed at /tmp/evil. An attacker who could control a Package.Spec.Source.URL or Deploy

PUBLISHED
Vendor
fission
Product
fission
Provider severity
HIGH
Conflicts
0

CVE-2026-50566

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability containers in the Fission function or builder namespace, scheduled under the executor's high-privilege service account — enabling container-sandbox escape, host filesystem and network access, and potential n

PUBLISHED
Vendor
fission
Product
fission
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50565

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken: false, so the kubelet auto-mounted the service-account token into every container in the pod — including the user-supplied builder image. This issue has been patched in version 1.24.0.

PUBLISHED
Vendor
fission
Product
fission
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50564

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods. The merge logic propagated hostNetwork, hostPID, hostIPC, container privileged, and serviceAccountName from the user-supplied podspec with no filtering, and Environment.Valida

PUBLISHED
Vendor
fission
Product
fission
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50563

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image. This issue has been patched in version 1.24.0.

PUBLISHED
Vendor
fission
Product
fission
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50562

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by privileged workflow_run jobs in .github/workflows/preview-docs-push.yml and .github/workflows/preview-fastgpt-push.yml, allowing attacker-controlled Docker images from the document/ tree or FastGPT build context to be pu

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
CRITICAL
Conflicts
1