Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-55175

35
FAUCET Score

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4.

First published: Jul 10, 2026Last modified: Jul 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 2025.3.0, < 2025.3.4CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2025.4.0, < 2025.4.4CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2026.0.0, < 2026.0.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2026.1.0, < 2026.1.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 42nd percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / spinnaker/spinnaker/commit/2d75818b85cc4c35144d5e5ed45e7340fcab5dfe
Patch
github.com / spinnaker/spinnaker/commit/bbc30c9b9034a056e95f012fa1b34e9fd703cae7
Patch
github.com / spinnaker/spinnaker/commit/de5a7a05af35aee19eb71d289cd0b77f67509009
Patch
github.com / spinnaker/spinnaker/commit/df32d568e82519d9f3896fc9007baba0077c87fd
Patch
github.com / spinnaker/spinnaker/commit/f5cec213f8cf207843ed5a6929395960a1ca094f
Patch
github.com / spinnaker/spinnaker/releases/tag/rosco-2025.3.4
Release Notes
github.com / spinnaker/spinnaker/releases/tag/rosco-2025.4.4
Release Notes
github.com / spinnaker/spinnaker/releases/tag/rosco-2026.0.3
Release Notes
github.com / spinnaker/spinnaker/releases/tag/rosco-2026.1.1
Release Notes
github.com / spinnaker/spinnaker/releases/tag/rosco-2026.2.0
Release Notes
github.com / spinnaker/spinnaker/security/advisories/GHSA-p68j-q7hf-3qcp
Third Party Advisory