CVE-2026-49821

HIGH
7.7CVSS v3
CVSS v2
0.23% EPSS (exploit probability)
CWE-441CWE

Description

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package.metadata.namespace. This issue has been patched in version 1.24.0.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references