<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alinuxfoundationspinnaker/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:15:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alinuxfoundationspinnaker/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Spinnaker rosco-manifests via Kustomize</title><link>https://feed.craftedsignal.io/briefs/2026-08-spinnaker-rosco-rce/</link><pubDate>Fri, 28 Aug 2026 21:15:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-spinnaker-rosco-rce/</guid><description>The Spinnaker rosco-manifests package is vulnerable to remote code execution (RCE) via improper YAML processing during Kustomize bake operations, allowing attackers to execute arbitrary code on rosco pods.</description><content:encoded><![CDATA[<p>Spinnaker's rosco-manifests package is susceptible to a high-severity remote code execution (RCE) vulnerability, tracked as CVE-2026-55175. The issue arises from improper YAML processing when the system performs Kustomize bake operations. An attacker capable of influencing the Kustomize input can trigger unsafe tag processing, resulting in the execution of arbitrary commands within the context of the rosco pods. This vulnerability is specific to the Kustomize provider within Spinnaker. Defenders should prioritize updating to the fixed versions or disabling Kustomize bake operations until patches can be applied. The vulnerability affects multiple versions of rosco-manifests across the 2025 and 2026 release cycles.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for remote code execution on the rosco pod, potentially leading to unauthorized system access, data exfiltration, or further compromise of the Spinnaker deployment environment. The vulnerability impacts organizations using Spinnaker for continuous delivery and CI/CD orchestration, particularly those utilizing Kustomize for manifest generation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade rosco-manifests to versions 2025.3.4, 2025.4.4, 2026.0.3, 2026.1.1, or later to remediate CVE-2026-55175.</li>
<li>Disable Kustomize bake operations in the Spinnaker configuration as an immediate workaround if patching cannot be performed immediately.</li>
<li>Audit logs for the rosco-manifests service to identify anomalous Kustomize bake requests or suspicious process execution originating from the rosco pod.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>ci-cd</category><category>spinnaker</category></item></channel></rss>