Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.
References
Configurations
Configuration 1 (hide)
|
History
21 Jul 2026, 19:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/spinnaker/spinnaker/commit/2d75818b85cc4c35144d5e5ed45e7340fcab5dfe - Patch | |
| References | () https://github.com/spinnaker/spinnaker/commit/bbc30c9b9034a056e95f012fa1b34e9fd703cae7 - Patch | |
| References | () https://github.com/spinnaker/spinnaker/commit/de5a7a05af35aee19eb71d289cd0b77f67509009 - Patch | |
| References | () https://github.com/spinnaker/spinnaker/commit/df32d568e82519d9f3896fc9007baba0077c87fd - Patch | |
| References | () https://github.com/spinnaker/spinnaker/commit/f5cec213f8cf207843ed5a6929395960a1ca094f - Patch | |
| References | () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.3.4 - Release Notes | |
| References | () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.4.4 - Release Notes | |
| References | () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.0.3 - Release Notes | |
| References | () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.1.1 - Release Notes | |
| References | () https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.2.0 - Release Notes | |
| References | () https://github.com/spinnaker/spinnaker/security/advisories/GHSA-p68j-q7hf-3qcp - Third Party Advisory | |
| CPE | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* | |
| First Time |
Linuxfoundation
Linuxfoundation spinnaker |
10 Jul 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 23:16
Updated : 2026-07-21 19:25
NVD link : CVE-2026-55175
Mitre link : CVE-2026-55175
CVE.ORG link : CVE-2026-55175
JSON object : View
Products Affected
linuxfoundation
- spinnaker
CWE
CWE-502
Deserialization of Untrusted Data
