CVE-2026-40564
Apache Flink Kubernetes Operator: unvalidated FlinkSessionJob jarURI allows SSRF and file reads
Technology
Apache Flink Kubernetes Operator
CVSS Score
6.5 / 10.0
Affected Versions
Apache Flink Kubernetes Operator 1.3.0 before 1.15.0
Upstream Fix
Kubernetes Operator 1.15.0
Published
May 26, 2026
OSSeva Coverage
Not covered
Description
The operator does not validate the jarURI of a FlinkSessionJob, so a user with permission to create the resource can read files from the operator pod's filesystem, pull content from any store reachable through Flink's filesystem layer, and point HTTP fetches at internal or link-local addresses, with no scheme allowlist or host check.
Is your Apache Flink Kubernetes Operator deployment affected?
If you're running Apache Flink Kubernetes Operator 1.3.0 before 1.15.0, you need this patch. Book a discovery call to get covered.