SCA: security update for io.spinnaker.clouddriver:clouddriver-artifacts, io.spinnaker.orca:orca-core (GHSA-8r8j-gfhg-fw38)

critical Tenable Self-Hosted Container Security Plugin ID 438854

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted
URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on
parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted
URLs. Note, Spinnaker found this not just in that CVE, but in the existing URL validations in Orca fromUrl
expression handling. This CVE impacts BOTH artifacts as a result. ### Patches This has been merged and
will be available in versions 2025.4.1, 2025.3.1, 2025.2.4 and 2026.0.0. ### Workarounds You can disable
the various artifacts on this system to work around these limits. (CVE-2026-25534)

Solution

Update the io.spinnaker.clouddriver:clouddriver-artifacts library and its related packages to version 2025.2.4 or later.

See Also

https://github.com/advisories/GHSA-8r8j-gfhg-fw38

Plugin Details

Severity: Critical

ID: 438854

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 3/16/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Percentile: 57.38

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:P

CVSS Score Source: CVE-2026-25534

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/16/2026

Vulnerability Publication Date: 3/16/2026

Reference Information

CVE: CVE-2026-25534

cwe: CWE-918