CVE-2026-50569
HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeURL and Prefix. Those two fields were validated at the CLI level only
(pkg/fission-cli/cmd/httptrigger/create.go:83). The post-CRD-modernization webhook for HTTPTrigger was retired in favor of API-server CEL — and CEL had no rules on those fields either — so an HTTPTrigger created via kubectl apply or
a direct Kubernetes REST API call bypassed every URL-level check.
A tenant with HTTPTrigger create permission could therefore create triggers whose RelativeURL or Prefix:
- was empty (with both fields unset, the trigger has no URL),
- did not start with /,
- was exactly / (claiming the entire router root),
- contained .. traversal segments (e.g. /api/../admin),
- collided with router-owned routes: /router-healthz, /readyz, /_version, /auth/login,
- collided with the router-internal function prefix /fission-function/<ns>/<name>.
Affected
- Project: github.com/fission/fission
- Versions: all versions through v1.24.0
- Audited commit: 647c141
- Component: pkg/apis/core/v1/validation.go:HTTPTriggerSpec.Validate (and the missing CEL on HTTPTriggerSpec)
- Configuration: default
Fix section (paste into the Fix / Patches field)
Fixed in v1.25.0 by:
- PR #3464 (commit 0deed6bf) — enforce the path-safety invariants at both admission layers so the API
server's CEL evaluation and the Go-side HTTPTriggerSpec.Validate() agree:
- Three +kubebuilder:validation:XValidation rules on HTTPTriggerSpec (the API server's CEL admission gate, regenerated into crds/v1/fission.io_httptriggers.yaml):
- at least one of relativeurl or prefix must be non-empty;
- relativeurl, when set, must start with /, must not be /, must contain no .. segment, must not be in the reserved exact-path set, and must not start with /fission-function/;
- prefix, when set, the same rules guarded by has(self.prefix).
- validateTriggerPath helper in pkg/apis/core/v1/validation.go, invok
⚡ Watch CVE-2026-50569
Get an email if CVE-2026-50569 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-50569)