VendorsLinux Foundationspinnakerall versions
Vulnerabilities

Linux Foundation The Linux Foundation Spinnaker

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-43832
Improper Access Control in spinnaker
Published 2022-01-04 · Modified
10.0EPSS 0.026
CVE-2026-32604
Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Published 2026-04-20 · Analyzed
9.9EPSS 0.006
CVE-2026-32613
Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling
Published 2026-04-20 · Analyzed
9.9EPSS 0.006
CVE-2020-9301
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.
Published 2020-12-11 · Modified
8.8EPSS 0.015
CVE-2026-44795
Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types
Published 2026-07-10 · Analyzed
8.8EPSS 0.010
CVE-2025-61916
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
Published 2026-01-05 · Analyzed
7.9EPSS 0.002
CVE-2026-55175
Spinnaker: Improper yaml processing on kustomize bake operations
Published 2026-07-10 · Analyzed
7.5EPSS 0.011
CVE-2022-23506
Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds
Published 2023-01-03 · Modified
7.5EPSS 0.005
CVE-2021-39143
Path Traversal in spinnaker
Published 2022-01-04 · Modified
7.1EPSS 0.003
CVE-2023-39348
Improper log output when using GitHub Status Notifications in spinnaker
Published 2023-08-28 · Modified
5.3EPSS 0.004