CVE-2026-44795High· 8.5▾ TwilightSpinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
1.0%
1.0% → 1.0%
There's an unsafe YAML processing vulnerability that bypasses safe deserialization. This impacts users when when performing:
The usage of a non-safe constructor use allows arbitrary loading of Java classes leading to RCE.
2025.3.3, 2026.0.3 and 2025.4.4.
Disable the CloudFormation system and cloudfoundry baking operations.
Join Spinnaker on Slack for more information!
io.spinnaker.rosco:rosco-core < 2025.3.3io.spinnaker.orca:orca-core < 2025.3.3io.spinnaker.rosco:rosco-core >= 2025.4.0, < 2025.4.4io.spinnaker.rosco:rosco-core >= 2026.0.0, < 2026.0.3io.spinnaker.orca:orca-core >= 2025.4.0, < 2025.4.4io.spinnaker.orca:orca-core >= 2026.0.0, < 2026.0.3Upgrade to a patched release:
io.spinnaker.rosco:rosco-core 2025.3.3io.spinnaker.orca:orca-core 2025.3.3io.spinnaker.rosco:rosco-core 2025.4.4io.spinnaker.rosco:rosco-core 2026.0.3io.spinnaker.orca:orca-core 2025.4.4io.spinnaker.orca:orca-core 2026.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2017-12149Critical· 9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…
CVE-2026-42027Critical· 9.8Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loa…
CVE-2020-5411High· 8.1When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution
CVE-2021-23758High· 8.1All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVE-2020-36182High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.