CVE-2026-25542
published 2026-04-21CVE-2026-25542: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.26%
18.6th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | kubevirt-ssp-operator-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-create-datavolume-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-disk-virt-customize-rhel9 | — | — |
| container-native-virtualization | kubevirt-template-validator-rhel9 | — | — |
| github.com | tektoncd_pipeline | >= 0.43.0 < 1.11.0 | 1.11.0 |
| linuxfoundation | tekton_pipelines | >= 0.43.0 < 1.11.0 | 1.11.0 |
| openshift-builds | openshift-builds-controller-rhel9 | — | — |
| openshift-builds | openshift-builds-git-cloner-rhel9 | — | — |
| openshift-builds | openshift-builds-image-bundler-rhel9 | — | — |
| openshift-builds | openshift-builds-image-processing-rhel9 | — | — |
| openshift-builds | openshift-builds-rhel9-operator | — | — |
| openshift-builds | openshift-builds-waiters-rhel9 | — | — |
| openshift-builds | openshift-builds-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel8 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel9 | — | — |
| openshift-pipelines | pipelines-git-init-rhel8 | — | — |
| openshift-pipelines | pipelines-git-init-rhel9 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel8 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel8 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
ghsa·2026-04-21
CVE-2026-25542 [MEDIUM] CWE-185 Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
## Summary
The Trusted Resources verification system matches a resource source string (`refSource.URI`) against `spec.resources[].pattern` using Go's `regexp.MatchString`. In Go, `regexp.MatchString` reports a match if the pattern matches **anywhere** in the input string. As a result, common unanchored patterns—including examples found in Tekton documentation—can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This may cause an unintended policy match and alter which verification mode or keys are applied.
## Affected Component
- **Repository:**
- **Commit:** `0133513db03dadb3cb08301d6b0330badcb63830`
- **Call site:** `pkg/trustedresources/verify.go:118–
VulDB
tektoncd pipeline up to 1.11.0 incorrect regex
vuldb·2026-04-21·CVSS 6.5
CVE-2026-25542 [MEDIUM] tektoncd pipeline up to 1.11.0 incorrect regex
A vulnerability classified as problematic was found in tektoncd pipeline up to 1.11.0. Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect regular expression.
This vulnerability is reported as CVE-2026-25542. The attack can be launched remotely. No exploit exists.
Red Hat
github.com/tektoncd/pipeline: Tekton Pipelines: Security bypass due to regular expression matching flaw
vendor_redhat·2026-04-21·CVSS 6.5
CVE-2026-25542 [MEDIUM] CWE-625 github.com/tektoncd/pipeline: Tekton Pipelines: Security bypass due to regular expression matching flaw
github.com/tektoncd/pipeline: Tekton Pipelines: Security bypass due to regular expression matching flaw
A flaw was found in Tekton Pipelines. An attacker can bypass trusted resource verification policies by crafting a malicious source string that contains a trusted pattern as a substring. This is due to the `regexp.MatchString` function in Go matching patterns anywhere within a string, rather than requiring an exact match. This vulnerability can lead to unintended policy matches, allowing an attacker to alter verification modes or keys and potentially compromise the integrity of Continuous Integration/Continuous Delivery (CI/CD) pipelines.
Package: openshift-builds/openshift-builds-controller-rhel9 (Builds for Red Hat OpenShift) - Fix deferred
Package: openshift-builds/openshift-builds-
No detection rules found.
No public exploits indexed.
2026-04-21
Published