CVE-2026-50545: Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
A stronger framing of the same root cause as GHSA-gx55-f84r-v3r7: the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fields into the generated pods.
References
- github.com/advisories/GHSA-wmgg-3p4h-48x7
- github.com/fission/fission/commit/8fa799417c77ce8a0189d9858bfe11ece29b84a6
- github.com/fission/fission/commit/e484df8460bb4e8026e24210120602aa7f181f64
- github.com/fission/fission/pull/3390
- github.com/fission/fission/pull/3391
- github.com/fission/fission/releases/tag/v1.24.0
- github.com/fission/fission/security/advisories/GHSA-wmgg-3p4h-48x7
- nvd.nist.gov/vuln/detail/CVE-2026-50545
Code Behaviors & Features
Detect and mitigate CVE-2026-50545 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →