LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-44795

linuxfoundation · spinnaker

Published
CVSS8.8
Severityhigh
WeaknessCWE-470
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44795

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44795.