CVE-2026-49822: Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
A low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent surveillance channel over any other namespace.
References
- github.com/advisories/GHSA-gc3j-79f2-7vvw
- github.com/fission/fission/commit/e2b92663499f4dc3a1e2d38178f39c3c65e0134a
- github.com/fission/fission/pull/3379
- github.com/fission/fission/releases/tag/v1.24.0
- github.com/fission/fission/security/advisories/GHSA-gc3j-79f2-7vvw
- nvd.nist.gov/vuln/detail/CVE-2026-49822
Code Behaviors & Features
Detect and mitigate CVE-2026-49822 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →