Skip to main content

Vendor/product archive

linuxfoundation / spinnaker CVEs

Beta · best-effort

10 CVEs tagged to linuxfoundation / spinnaker3 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-55175

Published Jul 10, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize ba…

CVSS 7.5 · High
evidence mentions
11
Buzz score
29.9
Vendor/product tagsBeta · best-effort

CVE-2026-44795

Published Jul 10, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization wh…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-32613

Published Apr 20, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically…

CVSS 9.9 · Critical
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-32604

Published Apr 20, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands…

CVSS 9.9 · Critical
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-61916

Published Jan 5, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primar…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39348

Published Aug 28, 2023

Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patc…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23506

Published Jan 3, 2023

Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43832

Published Jan 4, 2022

Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-39143

Published Jan 4, 2022

Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9301

Published Dec 11, 2020

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1