CVE-2026-44795
EUVD-2026-4308610.07.2026, 22:16
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linuxfoundation | spinnaker | 𝑥 < 2025.3.3 |
| linuxfoundation | spinnaker | 2025.4.0 ≤ 𝑥 < 2025.4.4 |
| linuxfoundation | spinnaker | 2026.0.0 ≤ 𝑥 < 2026.0.3 |
𝑥
= Vulnerable software versions
References