GITHUB-ACTIONS · JULY 2026 · EARLY WARNING

Nuclio <= 1.15.27 Vulnerability Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-V5PX-423J-PF7PSeverity: CRITICAL

Nuclio versions up to and including 1.15.27 are under investigation for a critical vulnerability that may allow remote code execution due to unsanitized cron trigger inputs.

What happened

Nuclio, a serverless framework, appears to have a critical vulnerability tracked as GHSA-V5PX-423J-PF7P. The issue reportedly arises from the Nuclio controller building a `curl` invocation string for each cron trigger and storing it as the `args` of a Kubernetes CronJob container. Unsanitized `event.headers` keys and `event.body` may lead to persistent remote code execution (RCE).

Professional software engineers using Nuclio should assess their exposure by checking if they are running a version up to and including 1.15.27. It is recommended to upgrade to a version that includes the fix for this vulnerability as soon as it becomes available.

For more detailed information, primary sources should be consulted. The GitHub Advisory Database entry for GHSA-V5PX-423J-PF7P provides additional context and is the primary source for this early warning.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If nuclio is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats