HIGH 7.5 Maven

Spinnaker: Improper yaml processing on kustomize bake operations

GHSA-p68j-q7hf-3qcp · CVE-2026-55175

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Kustomize bake operations allow unsafe tag processing. This can lead to RCE type exploits on the rosco pods when doing kustomize bakes. This ONLY is possible when using Kustomize. The simple solution is to block kustomize operations and instead use another provider.

Workarounds

Disable kustomize bakes

Ready to move

Start Securing

Free, no credit card | First findings in minutes