Spinnaker
This hub aggregates every CVE we track for Spinnaker. Use it to gauge the current risk picture and drill into individual advisories.
other
10
CVEs tracked
3
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4MEDIUM3CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2
0
0
2
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Spinnaker.
- CVE-2026-55175Spinnaker: Improper yaml processing on kustomize bake operations7.5
- CVE-2026-44795Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types8.8
- CVE-2026-32613Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling9.9
- CVE-2026-32604Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths9.9
- CVE-2025-61916Spinnaker vulnerable to SSRF due to improper restrictions on http from user input7.9
- CVE-2023-39348Improper log output when using GitHub Status Notifications in spinnaker4.0
- CVE-2022-23506Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds4.3
- CVE-2021-43832Improper Access Control in spinnaker10.0
- CVE-2021-39143Path Traversal in spinnaker6.6
- CVE-2020-9301Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of S...8.8
Product normalization is registry-driven with AI assist and human review. How it works