Tekton Pipelines
8 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Tekton Pipelines. Use it to gauge the current risk picture and drill into individual advisories.
Tekton Pipelines CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 5 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High2
- Medium4
- Low1
Latest CVEs
The 8 most recently published vulnerabilities affecting Tekton Pipelines.
- CVE-2026-40923Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check5.4
- CVE-2026-40924Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion6.5
- CVE-2026-40938Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE7.5
- CVE-2026-40161Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL7.7
- CVE-2026-25542Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching6.5
- CVE-2026-33211Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod9.6
- CVE-2026-33022Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun6.5
- CVE-2023-37264Pipelines do not validate child UIDs3.7
Product grouping is registry-driven, with AI assist and human review. How it works