Threat Advisory

Spinnaker Flaw Allows RCE on Rosco Pods via Kustomize Bakes

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity deserialization vulnerability affecting continuous delivery platform manifest baking components enables remote code execution during specific configuration processing tasks. Identified with a CVSS v3 score of 7.5, the flaw stems from unsafe tag processing during YAML parsing routines within automated manifest compilation engines. Organizations utilizing these deployment pipelines face potential system compromise if authenticated attackers supply malicious manifest configurations. Because successful exploitation permits arbitrary code execution within core service instances, immediate evaluation and remediation of vulnerable pipeline instances are strongly recommended to ensure underlying infrastructure integrity.

CVE-2026-55175: This deserialization flaw affects the manifest baking module of continuous delivery pipeline instances utilizing specific manifest processing integrations. The vulnerability exists within internal YAML parsing functions during automated deployment operations, allowing unsafe tag handling during processing. An authenticated attacker with low privileges can leverage this flaw to trigger remote code execution within target service pods. Successful exploitation provides full confidentiality, integrity, and availability impact over the underlying service deployment context.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity deserialization vulnerability affecting continuous delivery platform manifest baking components enables remote code execution during specific configuration processing tasks. Identified with a CVSS v3 score of 7.5, the flaw stems from unsafe tag processing during YAML parsing routines within automated manifest compilation engines. Organizations utilizing these deployment pipelines face potential system compromise if authenticated attackers supply malicious manifest configurations. Because successful exploitation permits arbitrary code execution within core service instances, immediate evaluation and remediation of vulnerable pipeline instances are strongly recommended to ensure underlying infrastructure integrity.

CVE-2026-55175: This deserialization flaw affects the manifest baking module of continuous delivery pipeline instances utilizing specific manifest processing integrations. The vulnerability exists within internal YAML parsing functions during automated deployment operations, allowing unsafe tag handling during processing. An authenticated attacker with low privileges can leverage this flaw to trigger remote code execution within target service pods. Successful exploitation provides full confidentiality, integrity, and availability impact over the underlying service deployment context.[emaillocker id="1283"]

Addressing this security risk requires upgrading vulnerable continuous delivery pipeline modules to patched versions or disabling affected integration bake operations. System administrators should verify processing dependencies and restrict untrusted inputs within deployment workflows to prevent unauthorized code execution.

RECOMMENDATION:

We recommend you to update rosco-manifests to version 2025.3.4, 2025.4.4, 2026.0.3, or 2026.1.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu