CVE-2026-55175

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*

History

21 Jul 2026, 19:25

Type Values Removed Values Added
References () https://github.com/spinnaker/spinnaker/commit/2d75818b85cc4c35144d5e5ed45e7340fcab5dfe - () https://github.com/spinnaker/spinnaker/commit/2d75818b85cc4c35144d5e5ed45e7340fcab5dfe - Patch
References () https://github.com/spinnaker/spinnaker/commit/bbc30c9b9034a056e95f012fa1b34e9fd703cae7 - () https://github.com/spinnaker/spinnaker/commit/bbc30c9b9034a056e95f012fa1b34e9fd703cae7 - Patch
References () https://github.com/spinnaker/spinnaker/commit/de5a7a05af35aee19eb71d289cd0b77f67509009 - () https://github.com/spinnaker/spinnaker/commit/de5a7a05af35aee19eb71d289cd0b77f67509009 - Patch
References () https://github.com/spinnaker/spinnaker/commit/df32d568e82519d9f3896fc9007baba0077c87fd - () https://github.com/spinnaker/spinnaker/commit/df32d568e82519d9f3896fc9007baba0077c87fd - Patch
References () https://github.com/spinnaker/spinnaker/commit/f5cec213f8cf207843ed5a6929395960a1ca094f - () https://github.com/spinnaker/spinnaker/commit/f5cec213f8cf207843ed5a6929395960a1ca094f - Patch
References () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.3.4 - () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.3.4 - Release Notes
References () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.4.4 - () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.4.4 - Release Notes
References () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.0.3 - () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.0.3 - Release Notes
References () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.1.1 - () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.1.1 - Release Notes
References () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.2.0 - () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.2.0 - Release Notes
References () https://github.com/spinnaker/spinnaker/security/advisories/GHSA-p68j-q7hf-3qcp - () https://github.com/spinnaker/spinnaker/security/advisories/GHSA-p68j-q7hf-3qcp - Third Party Advisory
CPE cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
First Time Linuxfoundation
Linuxfoundation spinnaker

10 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 23:16

Updated : 2026-07-21 19:25


NVD link : CVE-2026-55175

Mitre link : CVE-2026-55175

CVE.ORG link : CVE-2026-55175


JSON object : View

Products Affected

linuxfoundation

  • spinnaker
CWE
CWE-502

Deserialization of Untrusted Data