{"id":"GHSA-vchh-r53j-8mpw","summary":"Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks","details":"`HTTPTriggerSpec.Validate()` validated `Methods`, `FunctionReference`, `Host`, `IngressConfig`, and `CorsConfig`, but silently skipped `RelativeURL` and `Prefix`. Those two fields were validated at the CLI level only\n(`pkg/fission-cli/cmd/httptrigger/create.go:83`). The post-CRD-modernization webhook for HTTPTrigger was retired in favor of API-server CEL — and CEL had no rules on those fields either — so an HTTPTrigger created via `kubectl apply` or\na direct Kubernetes REST API call bypassed every URL-level check.\n\nA tenant with HTTPTrigger create permission could therefore create triggers whose `RelativeURL` or `Prefix`:\n\n- was empty (with both fields unset, the trigger has no URL),\n- did not start with `/`,\n- was exactly `/` (claiming the entire router root),\n- contained `..` traversal segments (e.g. `/api/../admin`),\n- collided with router-owned routes: `/router-healthz`, `/readyz`, `/_version`, `/auth/login`,\n- collided with the router-internal function prefix `/fission-function/\u003cns\u003e/\u003cname\u003e`.\n\n### Affected\n\n- Project: `github.com/fission/fission`\n- Versions: all versions through v1.24.0\n- Audited commit: `647c141`\n- Component: `pkg/apis/core/v1/validation.go:HTTPTriggerSpec.Validate` (and the missing CEL on `HTTPTriggerSpec`)\n- Configuration: default\n\nFix section (paste into the Fix / Patches field)\n\nFixed in [v1.25.0](https://github.com/fission/fission/releases/tag/v1.25.0) by:\n\n- [PR #3464](https://github.com/fission/fission/pull/3464) (commit [`0deed6bf`](https://github.com/fission/fission/commit/0deed6bf2af2a0c0c6094b25e1a0afad36773e3b)) — enforce the path-safety invariants at both admission layers so the API\nserver's CEL evaluation and the Go-side `HTTPTriggerSpec.Validate()` agree:\n  - Three `+kubebuilder:validation:XValidation` rules on `HTTPTriggerSpec` (the API server's CEL admission gate, regenerated into `crds/v1/fission.io_httptriggers.yaml`):\n    - at least one of `relativeurl` or `prefix` must be non-empty;\n    - `relativeurl`, when set, must start with `/`, must not be `/`, must contain no `..` segment, must not be in the reserved exact-path set, and must not start with `/fission-function/`;\n    - `prefix`, when set, the same rules guarded by `has(self.prefix)`.\n  - `validateTriggerPath` helper in `pkg/apis/core/v1/validation.go`, invoked from `HTTPTriggerSpec.Validate()`, mirrors the CEL rules so the CLI's early rejection and the router reconciler's status-Condition path match what the API\nserver admits.\n\nRegression coverage: a new `TestHTTPTriggerSpecValidate_Path` table in `pkg/apis/core/v1/validation_validators_test.go` exercises every PoC case from the advisory plus literal `..`-prefixed-segment positives that must remain allowed.","aliases":["CVE-2026-50569","GO-2026-6131"],"modified":"2026-08-24T00:37:07.200165050Z","published":"2026-07-28T20:16:00Z","database_specific":{"nvd_published_at":"2026-06-10T18:17:13Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-28T20:16:00Z"},"references":[{"type":"WEB","url":"https://github.com/fission/fission/security/advisories/GHSA-vchh-r53j-8mpw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50569"},{"type":"WEB","url":"https://github.com/fission/fission/pull/3464"},{"type":"WEB","url":"https://github.com/fission/fission/commit/0deed6bf3f26bc0f10e9130cd0d479b0b9f5f609"},{"type":"PACKAGE","url":"https://github.com/fission/fission"},{"type":"WEB","url":"https://github.com/fission/fission/releases/tag/v1.25.0"}],"affected":[{"package":{"name":"github.com/fission/fission","ecosystem":"Go","purl":"pkg:golang/github.com/fission/fission"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.24.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-vchh-r53j-8mpw/GHSA-vchh-r53j-8mpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}