CVE-2026-50566 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-50566 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-50566 is a critical authorization/sandbox-hardening bypass in github.com/fission/fission (CVSS 9.9). It lets a tenant with Environment create/update permissions submit a malicious Environment CRD that bypasses container security checks and can launch privileged or capability-boosted runtime/builder containers. In practical terms, this can lead to container escape, host access, and possible node or cluster compromise.
The issue is a follow-up bypass of earlier PodSpec hardening advisories. The admission webhook validated PodSpec fields, but missed standalone runtime.container and builder.container fields. Those containers were then merged without the same security-context sanitization.
Immediate Action
- Upgrade immediately to
github.com/fission/fission v1.24.0or later. If you cannot patch right away, treat all Environment create/update requests as high risk. - Restrict RBAC so only trusted administrators can create or update
environments.fission.ioresources. - Block dangerous security contexts with Kyverno or OPA Gatekeeper until patched. Reject
privileged: true,allowPrivilegeEscalation: true, and dangerous capability additions. - Isolate Fission namespaces with Kubernetes Pod Security Admission set to
restrictedwhere possible. - Review existing Environments for suspicious
runtime.containerorbuilder.containersettings and rotate any credentials exposed to those pods. - See the vendor fix and release notes: vendor patch PR and v1.24.0 release.
Affected Versions
github.com/fission/fission < 1.24.0vulnerablegithub.com/fission/fission 1.24.0+safeghcr.io/fission/fission:*<1.24.0*vulnerable Docker imagesghcr.io/fission/fission:1.24.0+safe Docker images
Resolution Guide
Go modules
go get github.com/fission/fission@v1.24.0
go mod tidy
Docker / Kubernetes
docker pull ghcr.io/fission/fission:v1.24.0
kubectl -n fission-system set image deployment/fission-controller \
controller=ghcr.io/fission/fission:v1.24.0
Helm (if you deploy Fission via chart)
helm upgrade --install fission fission/fission \
--namespace fission-system \
--set image.tag=v1.24.0
Hardening / policy example
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: deny-dangerous-fission-environments
spec:
validationFailureAction: Enforce
rules:
- name: deny-privileged-and-dangerous-capabilities
match:
resources:
kinds:
- Environment
validate:
message: "Dangerous container securityContext settings are not allowed."
pattern:
spec:
=(runtime):
=(container):
X(securityContext):
X(privileged): "false"
X(allowPrivilegeEscalation): "false"
=(builder):
=(container):
X(securityContext):
X(privileged): "false"
X(allowPrivilegeEscalation): "false"
Minimal code fix pattern (for maintainers backporting or reviewing the patch)
// Pseudocode: sanitize standalone containers too
func (e *Environment) Validate() error {
if e.Spec.Runtime.Container != nil {
if err := ValidateContainerSafety(e.Spec.Runtime.Container); err != nil {
return err
}
}
if e.Spec.Builder.Container != nil {
if err := ValidateContainerSafety(e.Spec.Builder.Container); err != nil {
return err
}
}
return nil
}
Rollback guidance
# If a bad environment was applied, delete it and recreate only after patching
kubectl delete environment -n default priv-escape-test
# If you must temporarily stop exposure, scale down Fission controllers
kubectl -n fission-system scale deployment --replicas=0 --all
Detection & Verification
Check installed version
kubectl -n fission-system get deploy -o jsonpath='{range .items[*]}{.metadata.name}{" "}{.spec.template.spec.containers[*].image}{"\n"}{end}'
go list -m github.com/fission/fission
Search for vulnerable patterns in manifests
grep -RIn --include='*.yaml' --include='*.yml' 'kind: Environment\|privileged:\|allowPrivilegeEscalation:\|capabilities:' .
Verify the fix
# This should now be rejected by admission
kubectl apply -f - <<'EOF'
apiVersion: fission.io/v1
kind: Environment
metadata:
name: test
spec:
version: 3
runtime:
image: ghcr.io/fission/python-env:latest
container:
name: test
securityContext:
privileged: true
EOF
Expected result after patch: the webhook should deny the resource with a validation error mentioning unsafe container security settings.
Dependency/audit checks
go mod why github.com/fission/fission
go env GOPATH
grep -RIn 'v1\.23\|v1\.22\|v1\.21' go.mod go.sum
Risk and Impact
This flaw can turn a normal tenant-level Fission deployment into a cluster compromise path. A malicious or compromised user with Environment write access can run containers with elevated privileges inside the executor’s high-privilege context, bypassing the intended sandbox.
Because the affected pods may have broad access to the function or builder namespace, the blast radius can include secrets, service accounts, internal network access, and potentially the underlying node. Even though there is no known active exploitation at this time, the severity is critical and the exposure is immediate for any unpatched deployment.