CVE-2026-44795: Linuxfoundation Spinnaker
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.
Affected products
- Linuxfoundation Spinnaker: before 2025.3.3 (fixed in 2025.3.3); from 2025.4.0, before 2025.4.4 (fixed in 2025.4.4); from 2026.0.0, before 2026.0.3 (fixed in 2026.0.3)
Published 2026-07-10. Last modified 2026-07-21.