CVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-10 22:16

Updated : 2026-07-21 14:01


NVD link : CVE-2026-44795

Mitre link : CVE-2026-44795

CVE.ORG link : CVE-2026-44795


JSON object : View

Products Affected

linuxfoundation

  • spinnaker
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CWE-502

Deserialization of Untrusted Data