CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50569

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-07-28
HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeURL and Prefix. Those two fields were validated at the CLI level only (pkg/fission-cli/cmd/httptrigger/create.go:83). The post-CRD-modernization webhook for HTTPTrigger was retired in favor of API-server CEL — and CEL had no rules on those fields either — so an HTTPTrigger created via kubectl apply or a direct Kubernetes REST API call bypassed every URL-level check. A tenant with HTTPTrigger create permission could therefore create triggers whose RelativeURL or Prefix: - was empty (with both fields unset, the trigger has no URL), - did not start with /, - was exactly / (claiming the entire router root), - contained .. traversal segments (e.g. /api/../admin), - collided with router-owned routes: /router-healthz, /readyz, /_version, /auth/login, - collided with the router-internal function prefix /fission-function/<ns>/<name>. Affected - Project: github.com/fission/fission - Versions: all versions through v1.24.0 - Audited commit: 647c141 - Component: pkg/apis/core/v1/validation.go:HTTPTriggerSpec.Validate (and the missing CEL on HTTPTriggerSpec) - Configuration: default Fix section (paste into the Fix / Patches field) Fixed in v1.25.0 by: - PR #3464 (commit 0deed6bf) — enforce the path-safety invariants at both admission layers so the API server's CEL evaluation and the Go-side HTTPTriggerSpec.Validate() agree: - Three +kubebuilder:validation:XValidation rules on HTTPTriggerSpec (the API server's CEL admission gate, regenerated into crds/v1/fission.io_httptriggers.yaml): - at least one of relativeurl or prefix must be non-empty; - relativeurl, when set, must start with /, must not be /, must contain no .. segment, must not be in the reserved exact-path set, and must not start with /fission-function/; - prefix, when set, the same rules guarded by has(self.prefix). - validateTriggerPath helper in pkg/apis/core/v1/validation.go, invok

⚡ Watch CVE-2026-50569

Get an email if CVE-2026-50569 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-50569

CVE.org record

Embed the live status

CVE-2026-50569 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50569 status](https://www.csirts.com/badge/CVE-2026-50569)](https://www.csirts.com/cve/CVE-2026-50569)