Spinnaker
Linux · 10 CVEs
Spinnaker: Improper yaml processing on kustomize bake operations
Jul 10, 2026
Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types
Jul 10, 2026
Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling
Apr 20, 2026
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and…
Apr 20, 2026
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
Jan 5, 2026
Improper log output when using GitHub Status Notifications in spinnaker
Aug 28, 2023
Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds
Jan 3, 2023
Improper Access Control in spinnaker
Jan 4, 2022
Path Traversal in spinnaker
Jan 4, 2022
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to versi…
Dec 11, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-55175 | Spinnaker: Improper yaml processing on kustomize bake operations | HIGH | 1.06% | Jul 10, 2026 |
| CVE-2026-44795 | Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types | HIGH | 1.01% | Jul 10, 2026 |
| CVE-2026-32613 | Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling | CRITICAL | 0.66% | Apr 20, 2026 |
| CVE-2026-32604 | Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths | CRITICAL | 0.77% | Apr 20, 2026 |
| CVE-2025-61916 | Spinnaker vulnerable to SSRF due to improper restrictions on http from user input | HIGH | 0.17% | Jan 5, 2026 |
| CVE-2023-39348 | Improper log output when using GitHub Status Notifications in spinnaker | MEDIUM | 0.38% | Aug 28, 2023 |
| CVE-2022-23506 | Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds | HIGH | 0.54% | Jan 3, 2023 |
| CVE-2021-43832 | Improper Access Control in spinnaker | CRITICAL | 2.57% | Jan 4, 2022 |
| CVE-2021-39143 | Path Traversal in spinnaker | HIGH | 0.34% | Jan 4, 2022 |
| CVE-2020-9301 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnera… | HIGH | 1.52% | Dec 11, 2020 |
Showing 1 to 10 of 10 CVEs