0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑25534, highlighting an SSRF flaw caused by Java’s URL parser’s handling of underscores in Spinnaker’s clouddriver and orca components, but does not provide PoC, exploit code, patch, or evidence of active exploitation.
PulsePatch.io@pulsepatchioDisclosure
Spinnaker’s clouddriver and orca components are vulnerable to a critical URL validation bypass (CVE‑2026‑25534), allowing underscores in hostnames; official patches are anticipated.
CVE@CVEnewDisclosure
The post reports that Spinnaker’s updated URL validation logic has a flaw leading to CVE‑2026‑25534, but does not provide PoC, exploit, active exploitation, patch, or detailed technical info.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The post announces a newly identified CVE (2026-25534) involving a URL validation bypass in Spinnaker, but does not provide PoC, exploit code, or patch details.
The Hacker Wire@TheHackerWirePatch
CVE-2026-25534 is a critical flaw in Spinnaker’s URL validation for clouddriver, caused by improper handling of Java URL objects. The vendor has addressed the issue by updating its validation logic to sanitize user‑supplied URLs.
CVEFind.com@CveFindComPatch
Spinnaker’s CVE-2026-25534, a critical URL‑validation bypass, has been patched in multiple versions with available workarounds, though no PoC or active exploitation details are disclosed.