๐Ÿ” CVE Alert

CVE-2026-50565

MEDIUM 4.9

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken: false, so the kubelet auto-mounted the service-account token into every container in the pod โ€” including the user-supplied builder image. This issue has been patched in version 1.24.0.

CWE CWE-250 CWE-269 CWE-538
Vendor fission
Product fission
Published Jun 10, 2026
Last Updated Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for fission fission

Be the first to know when new medium vulnerabilities affecting fission fission are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

fission / fission
< 1.24.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fission/fission/security/advisories/GHSA-8wcj-mfrc-jx5q github.com: https://github.com/fission/fission/pull/3390 github.com: https://github.com/fission/fission/releases/tag/v1.24.0