PatchSiren cyber security CVE debrief
CVE-2026-40564 Apache Software Foundation CVE debrief
Apache Flink Kubernetes Operator versions 1.3.0 through 1.14.x contain a vulnerability where the FlinkSessionJob jarURI parameter is not validated to ensure it points to user-owned files or addresses. This allows users with Custom Resource (CR) create permissions to read files from the operator pod's filesystem and pull content from any backing store reachable through Flink's pluggable filesystem layer. Additionally, for HTTP/HTTPS addresses, there is no allowlist on the URI scheme, no host check, no IP-range restriction, and no protection against pointing the URI at internal or link-local addresses. The vulnerability was published on 2026-05-26.
- Vendor
- Apache Software Foundation
- Product
- Apache Flink Kubernetes Operator
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-06-02
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-06-02
Who should care
Organizations running Apache Flink Kubernetes Operator versions 1.3.0 through 1.14.x, particularly those with multi-tenant Kubernetes environments where users have Custom Resource creation permissions. Security teams should prioritize patching due to the potential for sensitive file disclosure and internal network reconnaissance via SSRF.
Technical summary
The Apache Flink Kubernetes Operator fails to validate the FlinkSessionJob jarURI parameter, allowing attackers with CR create permissions to read arbitrary files from the operator pod filesystem and perform server-side request forgery against internal and external resources. The vulnerability affects versions 1.3.0 through 1.14.x and is resolved in version 1.15.0.
Defensive priority
High
Recommended defensive actions
- Upgrade Apache Flink Kubernetes Operator to version 1.15.0 or later
- Review and audit FlinkSessionJob Custom Resources for unauthorized jarURI values
- Implement network segmentation to restrict operator pod access to sensitive internal resources
- Monitor for suspicious outbound connections from Flink Kubernetes Operator pods
- Validate that users with CR create permissions follow principle of least privilege
Evidence notes
The vulnerability description indicates that the jarURI parameter lacks validation, enabling unauthorized file access and SSRF. The affected versions are explicitly stated as 1.3.0 before 1.15.0. The official fix is available in version 1.15.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40564 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40564
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40564 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40564
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/jvxs2kh2o60sl7qkl5nss4r5phzfl4cz
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.