| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-69rw-45wj-g4v6 | Spinnaker: RCE via expression parsing due to unrestricted context handling |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spinnaker
Spinnaker spinnaker |
|
| Vendors & Products |
Spinnaker
Spinnaker spinnaker |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled the ability to invoke commands, access files, etc. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable echo entirely. | |
| Title | Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T03:56:18.686Z
Reserved: 2026-03-12T14:54:24.271Z
Link: CVE-2026-32613
Updated: 2026-04-21T18:04:25.577Z
Status : Awaiting Analysis
Published: 2026-04-20T21:16:32.623
Modified: 2026-04-21T16:20:24.180
Link: CVE-2026-32613
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:47:15Z
Github GHSA