CVE-2026-40161
published 2026-04-21CVE-2026-40161: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.26%
18.1th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | kubevirt-tekton-tasks-create-datavolume-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-disk-virt-customize-rhel9 | — | — |
| github.com | tektoncd_pipeline | 1.0.0 – 1.10.0 | — |
| linuxfoundation | tekton_pipelines | 1.0.0 – 1.10.0 | — |
| openshift-builds | openshift-builds-controller-rhel9 | — | — |
| openshift-builds | openshift-builds-git-cloner-rhel9 | — | — |
| openshift-builds | openshift-builds-image-bundler-rhel9 | — | — |
| openshift-builds | openshift-builds-image-processing-rhel9 | — | — |
| openshift-builds | openshift-builds-rhel9-operator | — | — |
| openshift-builds | openshift-builds-waiters-rhel9 | — | — |
| openshift-builds | openshift-builds-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel9 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-opc-rhel9 | — | — |
| openshift-pipelines | pipelines-operator-proxy-rhel9 | — | — |
| openshift-pipelines | pipelines-operator-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-pipelines-as-code-cli-rhel9 | — | — |
| openshift-pipelines | pipelines-pipelines-as-code-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-pipelines-as-code-watcher-rhel9 | — | — |
| openshift-pipelines | pipelines-pruner-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-results-api-rhel9 | — | — |
| openshift-pipelines | pipelines-results-watcher-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
tektoncd pipeline up to 1.10.0 insertion of sensitive information into sent data (ID 9608 / EUVD-2026-24165)
vuldb·2026-04-21·CVSS 7.7
CVE-2026-40161 [HIGH] tektoncd pipeline up to 1.10.0 insertion of sensitive information into sent data (ID 9608 / EUVD-2026-24165)
A vulnerability was found in tektoncd pipeline up to 1.10.0. It has been declared as problematic. The affected element is an unknown function. The manipulation results in insertion of sensitive information into sent data.
This vulnerability was named CVE-2026-40161. The attack may be performed from remote. There is no available exploit.
GHSA
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
ghsa·2026-04-21
CVE-2026-40161 [HIGH] CWE-201 Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
### Summary
The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled `serverURL` when the user omits the `token` parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing `serverURL` to an attacker-controlled endpoint.
### Details
The git resolver's `ResolveAPIGit()` function in `pkg/resolution/resolver/git/resolver.go` constructs an SCM client using the user-supplied `serverURL` and a token obtained via `getAPIToken()`.
When the user provides `serverURL` but omits the `token` parameter:
1. `getSCMTypeAndServerURL()` reads `serverURL` directly
Red Hat
github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL
vendor_redhat·2026-04-21·CVSS 7.7
CVE-2026-40161 [HIGH] CWE-918 github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL
github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL
A flaw was found in Tekton Pipelines. A tenant with permissions to create TaskRun or PipelineRun resources can exploit this vulnerability. By omitting the Git API token parameter and pointing the serverURL to an attacker-controlled endpoint, the system-configured Git API token (such as a GitHub Personal Access Token or GitLab token) can be sent to the attacker. This information disclosure allows for the exfiltration of sensitive API tokens.
Package: openshift-builds/openshift-builds-controller-rhel9 (Builds for Red Hat OpenShift) - Affected
Package: openshift-builds/openshift-builds-git-cloner-rhel9 (Builds for Red Hat OpenShift) - Affected
Package: openshift-builds/ope
No detection rules found.
No public exploits indexed.
2026-04-21
Published