CVE-2026-49821: Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Fission’s buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package.metadata.namespace.
References
- github.com/advisories/GHSA-vjhc-cf4p-72q4
- github.com/fission/fission/commit/e2b92663499f4dc3a1e2d38178f39c3c65e0134a
- github.com/fission/fission/pull/3379
- github.com/fission/fission/releases/tag/v1.24.0
- github.com/fission/fission/security/advisories/GHSA-vjhc-cf4p-72q4
- nvd.nist.gov/vuln/detail/CVE-2026-49821
Code Behaviors & Features
Detect and mitigate CVE-2026-49821 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →