CVE-2026-55175: Linuxfoundation Spinnaker

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.

Affected products

  • Linuxfoundation Spinnaker: from 2025.3.0, before 2025.3.4 (fixed in 2025.3.4); from 2025.4.0, before 2025.4.4 (fixed in 2025.4.4); from 2026.0.0, before 2026.0.3 (fixed in 2026.0.3); from 2026.1.0, before 2026.1.1 (fixed in 2026.1.1)

Published 2026-07-10. Last modified 2026-07-21.