CVE-2026-40564 is an insufficient input validation issue in Apache Flink Kubernetes Operator affecting versions 1.3.0 through 1.14.x, fixed in 1.15.0. The vulnerable component is the FlinkSessionJob jarURI handling. The operator did not validate that jarURI references were limited to user-owned files or approved locations. As a result, a user with permission to create the relevant custom resource could supply arbitrary file or network-backed URIs. This allowed access to files on the operator pod filesystem and retrieval of content from backing stores reachable through Flink's pluggable filesystem layer. For HTTP/HTTPS fetching, the implementation also lacked URI scheme allowlisting, host validation, IP-range restrictions, and protections against internal or link-local destinations, enabling SSRF behavior in addition to local file access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact end-to-end reproducer for CVE-2026-40564, an SSRF issue in Apache Flink Kubernetes Operator. It is not a general exploit framework; the main logic is in a Makefile that automates environment setup, vulnerable operator installation, deployment of a benign Flink session cluster, injection of a malicious FlinkSessionJob, and verification of the resulting outbound request. Repository structure: - Makefile: primary exploit orchestration. It creates a kind cluster, installs flink-kubernetes-operator via Helm, patches DNS behavior, applies manifests, substitutes an attacker-controlled jarURI into the vulnerable session job, and verifies SSRF either through webhook.site APIs or operator logs. - README.md: detailed vulnerability explanation, affected versions, call chain, usage instructions, impact discussion, and suggested remediation. - manifests/session-cluster.yaml: creates a FlinkDeployment named session-cluster so the operator will reconcile session jobs. - manifests/vulnerable-sessionjob.yaml: malicious FlinkSessionJob template with spec.job.jarURI pointing to an attacker-controlled URL. Exploit capability: The exploit abuses the operator's handling of FlinkSessionJob.spec.job.jarURI. By creating a FlinkSessionJob with jarURI set to an arbitrary URI, the attacker causes the operator pod to fetch that URI from its own execution context. The README states the vulnerable call chain is SessionJobReconciler.deploy -> submitJobToSessionCluster -> uploadJar -> ArtifactManager.fetch -> HttpArtifactFetcher.fetch. The Makefile confirms this by applying a crafted CR and then checking either webhook.site captures or operator logs for HttpArtifactFetcher activity. The exploit supports arbitrary attacker-supplied targets through SSRF_URL/WEBHOOK_URL and explicitly documents HTTP, HTTPS, file://, and storage/filesystem schemes such as s3://. Example impacts described in the repo include reaching AWS IMDS at 169.254.169.254, internal cluster services such as 10.0.0.1:6443, and local files like /etc/passwd. Verification is strongest for webhook.site targets because the Makefile polls webhook.site's REST API and prints captured GET requests, including user agent and source IP. Overall, this is an operational PoC/reproducer for a Kubernetes operator SSRF vulnerability. It does not deliver post-exploitation code execution; instead, it reliably demonstrates forced outbound fetches from the operator pod and documents how that primitive could be leveraged for metadata access, internal service reachability, blind port scanning, or access to storage/filesystem backends available to the operator.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.