CVE Tools

Pipeline\

48 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Pipeline\, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Pipeline\ CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Pipeline\ CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-045
2026-051
2026-062
2026-070
2026-080
2026-090

Severity

How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical48%
  • High2144%
  • Medium2246%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Pipeline\.

  1. CVE-2026-57284Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types r...4.3
  2. CVE-2026-57283A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration othe...4.3
  3. CVE-2026-48921Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by...7.5
  4. CVE-2026-40923Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check5.4
  5. CVE-2026-40924Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion6.5
  6. CVE-2026-40938Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE7.5
  7. CVE-2026-40161Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL7.7
  8. CVE-2026-25542Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching6.5
  9. CVE-2026-33211Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod9.6
  10. CVE-2026-33022Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun6.5
  11. CVE-2024-52551Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing a...8.0
  12. CVE-2024-52550Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attack...8.0
  13. CVE-2023-37264Pipelines do not validate child UIDs3.7
  14. CVE-2023-32977Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by ...5.4
  15. CVE-2023-25762Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vu...5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store