CVE-2026-44795

🟡 Monitoruj

Niebezpieczne przetwarzanie YAML w Spinnaker umożliwia zdalne wykonanie kodu.

CVSS
8.8
EPSS
1.0%
Exploit
none
Vendor
linuxfoundation
Opis źródłowy (NVD)

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.

deserialization rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.0%
Opublikowano (NVD)2026-07-10 22:16:41 UTC
Ostatnia modyfikacja (NVD)2026-07-21 14:01:22 UTC
Referencje