Vulnerability Description
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Spinnaker | < 2025.3.3 |
Related Weaknesses (CWE)
References
- https://github.com/spinnaker/spinnaker/commit/4cbe1d5fea9df573aadfd8b093fb4b594bPatch
- https://github.com/spinnaker/spinnaker/commit/e57c0db4584b398473a7bbb19402ce6c1ePatch
- https://github.com/spinnaker/spinnaker/commit/f69d7b534d068ed74d0d3a1fbf17e2c945Patch
- https://github.com/spinnaker/spinnaker/security/advisories/GHSA-c8q4-9h32-2ww8Third Party Advisory
FAQ
What is CVE-2026-44795?
CVE-2026-44795 is a vulnerability with a CVSS score of 8.8 (HIGH). Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormati...
How severe is CVE-2026-44795?
CVE-2026-44795 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44795?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Spinnaker.