Impact
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This vulnerability, a deserialization flaw (CWE‑470, CWE‑502), undermines confidentiality, integrity, and availability of the affected instance.
Affected Systems
Any installation of Spinnaker prior to versions 2026.1.0, 2026.0.3, 2025.4.4, or 2025.3.3 is affected. Upgrading to any of those versions or later resolves the issue.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is 1%, showing a measurable but low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a malicious YAML file supplied in CloudFormation or CloudFoundry deployments that the system processes without proper restrictions, allowing arbitrary class loading and remote code execution.
OpenCVE Enrichment
Github GHSA