Security Advisory

CVE-2026-44795

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 21:49:27
Last updated 2026-07-15 03:59:56
Assigner GitHub_M
CVSS score 8.8
State PUBLISHED

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.