Spinnaker
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Spinnaker. Use it to gauge the current risk picture and drill into individual advisories.
Spinnaker CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High4
- Medium3
Latest CVEs
The 10 most recently published vulnerabilities affecting Spinnaker.
- CVE-2026-55175Spinnaker: Improper yaml processing on kustomize bake operations7.5
- CVE-2026-44795Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types8.8
- CVE-2026-32613Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling9.9
- CVE-2026-32604Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths9.9
- CVE-2025-61916Spinnaker vulnerable to SSRF due to improper restrictions on http from user input7.9
- CVE-2023-39348Improper log output when using GitHub Status Notifications in spinnaker4.0
- CVE-2022-23506Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds4.3
- CVE-2021-43832Improper Access Control in spinnaker10.0
- CVE-2021-39143Path Traversal in spinnaker6.6
- CVE-2020-9301Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of S...8.8
Product grouping is registry-driven, with AI assist and human review. How it works