LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-55175

linuxfoundation · spinnaker

Published
CVSS7.5
Severityhigh
WeaknessCWE-502
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-55175

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-55175.