Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40938 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40938)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40938). Successful exploitation can lead to full system takeover. Exploitable via ``revision``. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-40924 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40924)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40924). Risk of unauthorized operations or information disclosure. Exploitable via ``FetchHttpResource``. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-40923 |
|
Path Traversal in github.com/tektoncd/pipeline (CVE-2026-40923)
path traversal in github.com/tektoncd/pipeline (CVE-2026-40923). Risk of unauthorized operations or information disclosure. Exploitable via ``strings.HasPrefix``. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-40161 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40161)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40161). Confidential information can be exposed externally. Exploitable via ``serverURL``. Mitigation: upgrade to `1.11.1` or later.
|
| CVE-2026-25542 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-25542)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-25542). Data can be tampered with by attackers. Exploitable via ``refSource.URI``. Mitigation: upgrade to `1.11.1` or later.
|