VYPR
High severity8.8NVD Advisory· Published Jul 10, 2026· Updated Jul 21, 2026

CVE-2026-44795

CVE-2026-44795

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Spinnaker/Spinnakerinferred2 versions
    = 2025.3.3 / 2026.0.3 / 2025.4.4+ 1 more
    • (no CPE)range: = 2025.3.3 / 2026.0.3 / 2025.4.4
    • (no CPE)range: before 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3
  • cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
    Range: <2025.3.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.