Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 59.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-44795


Contact Us

Shodan ® - All rights reserved