Linux / Spinnaker
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55175 | Spinnaker: Improper yaml processing on kustomize bake operations | HIGH | 7.5 | Jul 10, 2026 |
| CVE-2026-44795 | Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types | HIGH | 8.8 | Jul 10, 2026 |
| CVE-2026-32613 | Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling | CRITICAL | 10.0 | Apr 20, 2026 |
| CVE-2026-32604 | Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths | CRITICAL | 10.0 | Apr 20, 2026 |
| CVE-2025-61916 | Spinnaker vulnerable to SSRF due to improper restrictions on http from user input | HIGH | 7.9 | Jan 5, 2026 |
| CVE-2023-39348 | Improper log output when using GitHub Status Notifications in spinnaker | MEDIUM | 5.3 | Aug 28, 2023 |
| CVE-2022-23506 | Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds | HIGH | 7.5 | Jan 3, 2023 |
| CVE-2021-43832 | Improper Access Control in spinnaker | CRITICAL | 10.0 | Jan 4, 2022 |
| CVE-2021-39143 | Path Traversal in spinnaker | HIGH | 7.1 | Jan 4, 2022 |
| CVE-2020-9301 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnera… | HIGH | 8.8 | Dec 11, 2020 |
Showing 1 to 10 of 10 CVEs