CVE-2026-25534Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs. Note, Spinnaker found this not just in that CVE, but in the existing URL validations in Orca fromUrl expression handling. This CVE impacts BOTH artifacts as a result. ### Patches This has been merged and will be available in versions 2025.4.1, 2025.3.1, 2025.2.4 and 2026.0.0. ### Workarounds You can disable the various artifacts on this system to work around these limits.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-17); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-17: 5Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-17: 2Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-17: 4Technical Details · 2026-03-20: 103-1703-20
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-175
Disclosure3Patch2
2026-03-201
Disclosure1
Full discourse6 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25534: Spinnaker clouddriver and orca U... Java's URL parser chokes on underscores, turning Spinnaker's "fixed" URL validation into Swiss cheese—SSRF bypass via h... https://zerodaysignal.com/vulnerability/CVE-2026-25534 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑25534, highlighting an SSRF flaw caused by Java’s URL parser’s handling of underscores in Spinnaker’s clouddriver and orca components, but does not provide PoC, exploit code, patch, or evidence of active exploitation.

    0101187
    152 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical URL validation bypass (CVE-2026-25534) affects `Spinnaker` clouddriver and orca components, allowing underscore usage in hostnames. Monitor for official patches. #Spinnaker #CloudSecurity #Vulnerability https://www.pulsepatch.io/posts/cve-2026-25534-spinnaker-url-validation-bypass

    Post summary

    Spinnaker’s clouddriver and orca components are vulnerable to a critical URL validation bypass (CVE‑2026‑25534), allowing underscores in hostnames; official patches are anticipated.

    0000031
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25534 ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objec… https://www.cve.org/CVERecord?id=CVE-2026-25534

    Post summary

    The post reports that Spinnaker’s updated URL validation logic has a flaw leading to CVE‑2026‑25534, but does not provide PoC, exploit, active exploitation, patch, or detailed technical info.

    00000103
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25534 - Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames Intel Report: https://ift.tt/RD1CVxA

    Post summary

    The post announces a newly identified CVE (2026-25534) involving a URL validation bypass in Spinnaker, but does not provide PoC, exploit code, or patch details.

    0000028
    336 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🔴 CVE-2026-25534 - Critical ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly h... https://www.thehackerwire.com/vulnerability/CVE-2026-25534/ https://t.co/HW6Y4vaE3A

    Post summary

    CVE-2026-25534 is a critical flaw in Spinnaker’s URL validation for clouddriver, caused by improper handling of Java URL objects. The vendor has addressed the issue by updating its validation logic to sanitize user‑supplied URLs.

    0000043
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25534: CRITICAL] Spinnaker's update missed issues in URL validation, leading to CVE bypass. Patched in versions 2025.4.1, 2025.3.1, 2025.2.4, and 2026.0.0. Workarounds available.#cve,CVE-2026-25534,#cybersecurity https://cvefind.com/CVE-2026-25534

    Post summary

    Spinnaker’s CVE-2026-25534, a critical URL‑validation bypass, has been patched in multiple versions with available workarounds, though no PoC or active exploitation details are disclosed.

    0000073
    602 followersView on X

Explore more