CVE-2025-61916
7.9 · HIGHOverview
CVE-2025-61916 is a high-severity vulnerability affecting linuxfoundation spinnaker. It was published on January 5, 2026 and has a CVSS 3.1 base score of 7.9 (HIGH).
This vulnerability has a CVSS 3.1 base score of 7.9, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.
Technical Description
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other methods to extract things LIKE idmsv1 authentication data. This also includes calling internal spinnaker API's via a get and similar endpoints. Further, depending upon the artifact in question, auth data may be exposed to arbitrary endpoints (e.g. GitHub auth headers) leading to credentials exposure. To trigger this, a spinnaker installation MUST have two things. The first is an artifact enabled that allows user input. This includes GitHub file artifacts, BitBucket, GitLab, HTTP artifacts and similar artifact providers. JUST enabling the http artifact provider will add a "no-auth" http provider that could be used to extract link local data (e.g. AWS Metadata information). The se
Remediation
Check the references section for vendor advisories and patches from linuxfoundation. Update spinnaker to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| linuxfoundation | spinnaker | >= 0, < 2025.1.6 | Affected |
Frequently Asked Questions
What is CVE-2025-61916?
CVE-2025-61916 is a high-severity vulnerability affecting linuxfoundation spinnaker. It was published on January 5, 2026 and has a CVSS 3.1 base score of 7.9 (HIGH).
How severe is CVE-2025-61916?
This vulnerability has a CVSS 3.1 base score of 7.9, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.
How do I fix or remediate CVE-2025-61916?
Check the references section for vendor advisories and patches from linuxfoundation. Update spinnaker to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2025-61916?
CyberStrike's AI-powered security agents can automatically detect CVE-2025-61916 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.