Back to Vulnerability Directory
MEDIUMNot covered

CVE-2026-40564

Apache Flink Kubernetes Operator: unvalidated FlinkSessionJob jarURI allows SSRF and file reads

Technology

Apache Flink Kubernetes Operator

CVSS Score

6.5 / 10.0

Affected Versions

Apache Flink Kubernetes Operator 1.3.0 before 1.15.0

Upstream Fix

Kubernetes Operator 1.15.0

Published

May 26, 2026

OSSeva Coverage

Not covered

Description

The operator does not validate the jarURI of a FlinkSessionJob, so a user with permission to create the resource can read files from the operator pod's filesystem, pull content from any store reachable through Flink's filesystem layer, and point HTTP fetches at internal or link-local addresses, with no scheme allowlist or host check.

Upstream record: NVD · CVE.org

Is your Apache Flink Kubernetes Operator deployment affected?

If you're running Apache Flink Kubernetes Operator 1.3.0 before 1.15.0, you need this patch. Book a discovery call to get covered.