Tekton pipelines
This hub aggregates every CVE we track for Tekton pipelines. Use it to gauge the current risk picture and drill into individual advisories.
other
8
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH2LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
5
0
0
0
0
0
2024-102026-09
Latest CVEs
The 8 most recently published vulnerabilities affecting Tekton pipelines.
- CVE-2026-40923Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check5.4
- CVE-2026-40924Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion6.5
- CVE-2026-40938Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE7.5
- CVE-2026-40161Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL7.7
- CVE-2026-25542Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching6.5
- CVE-2026-33211Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod9.6
- CVE-2026-33022Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun6.5
- CVE-2023-37264Pipelines do not validate child UIDs3.7
Product normalization is registry-driven with AI assist and human review. How it works