VendorsLinux Foundationtekton_pipelinesall versions
Vulnerabilities

Linux Foundation Tekton Pipelines

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-33211
Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
Published 2026-03-23 · Modified
9.6EPSS 0.007
CVE-2026-40938
Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
Published 2026-04-21 · Modified
8.5EPSS 0.009
CVE-2026-40161
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
Published 2026-04-21 · Modified
7.7EPSS 0.004
CVE-2026-40924
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Published 2026-04-21 · Modified
6.5EPSS 0.005
CVE-2026-33022
Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun
Published 2026-03-20 · Analyzed
6.5EPSS 0.004
CVE-2026-25542
Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
Published 2026-04-21 · Modified
6.5EPSS 0.004
CVE-2026-40923
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Published 2026-04-21 · Modified
5.4EPSS 0.003
CVE-2023-37264
Pipelines do not validate child UIDs
Published 2023-07-07 · Modified
4.3EPSS 0.004