Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.spinnaker.rosco/rosco-core
  4. ›
  5. CVE-2026-44795

CVE-2026-44795: Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types

June 22, 2026 (updated August 5, 2026)

There’s an unsafe YAML processing vulnerability that bypasses safe deserialization. This impacts users when when performing:

  • CloudFormation deployments
  • CloudFoundry Baking

The usage of a non-safe constructor use allows arbitrary loading of Java classes leading to RCE.

References

  • github.com/advisories/GHSA-c8q4-9h32-2ww8
  • github.com/spinnaker/spinnaker/commit/4cbe1d5fea9df573aadfd8b093fb4b594b354ee5
  • github.com/spinnaker/spinnaker/commit/e57c0db4584b398473a7bbb19402ce6c1e89b627
  • github.com/spinnaker/spinnaker/commit/f69d7b534d068ed74d0d3a1fbf17e2c945d36e5e
  • github.com/spinnaker/spinnaker/security/advisories/GHSA-c8q4-9h32-2ww8
  • nvd.nist.gov/vuln/detail/CVE-2026-44795

Code Behaviors & Features

Detect and mitigate CVE-2026-44795 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2025.3.3, all versions starting from 2025.4.0 before 2025.4.4, all versions starting from 2026.0.0 before 2026.0.3

Fixed versions

  • 2025.3.3
  • 2025.4.4
  • 2026.0.3

Solution

Upgrade to versions 2025.3.3, 2025.4.4, 2026.0.3 or above.

Impact 8.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
  • CWE-502: Deserialization of Untrusted Data

Source file

maven/io.spinnaker.rosco/rosco-core/CVE-2026-44795.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:32 +0000.