VendorsLinux Foundationtekton_pipelinesany version
Vulnerabilities

Linux Foundation Tekton Pipelines any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-33211
Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod
Published 2026-03-23 · Modified
9.6EPSS 0.006
CVE-2026-40938
Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
Published 2026-04-21 · Modified
8.5EPSS 0.008
CVE-2026-40161
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
Published 2026-04-21 · Modified
7.7EPSS 0.003
CVE-2026-33022
Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun
Published 2026-03-20 · Analyzed
6.5EPSS 0.004
CVE-2026-40924
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Published 2026-04-21 · Modified
6.5EPSS 0.003
CVE-2026-25542
Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
Published 2026-04-21 · Modified
6.5EPSS 0.003
CVE-2026-40923
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Published 2026-04-21 · Modified
5.4EPSS 0.002
CVE-2023-37264
Pipelines do not validate child UIDs
Published 2023-07-07 · Modified
4.3EPSS 0.004