CVE-2026-40923
published 2026-04-21CVE-2026-40923: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2…
PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.22%
12.8th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path traversal components. The restriction check uses strings.HasPrefix without filepath.Clean, so a path like /tekton/home/../results passes validation but resolves to /tekton/results at runtime. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | kubevirt-ssp-operator-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-create-datavolume-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-disk-virt-customize-rhel9 | — | — |
| container-native-virtualization | kubevirt-template-validator-rhel9 | — | — |
| github.com | tektoncd_pipeline | >= 0 < 1.11.1 | 1.11.1 |
| linuxfoundation | tekton_pipelines | < 1.11.1 | 1.11.1 |
| openshift-builds | openshift-builds-controller-rhel9 | — | — |
| openshift-builds | openshift-builds-git-cloner-rhel9 | — | — |
| openshift-builds | openshift-builds-image-bundler-rhel9 | — | — |
| openshift-builds | openshift-builds-image-processing-rhel9 | — | — |
| openshift-builds | openshift-builds-rhel9-operator | — | — |
| openshift-builds | openshift-builds-waiters-rhel9 | — | — |
| openshift-builds | openshift-builds-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel8 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel9 | — | — |
| openshift-pipelines | pipelines-git-init-rhel8 | — | — |
| openshift-pipelines | pipelines-git-init-rhel9 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel8 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel8 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel9 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
github.com/tektoncd/pipeline: Tekton Pipelines: Unauthorized access and information disclosure via path validation bypass
vendor_redhat·2026-04-21·CVSS 5.4
CVE-2026-40923 [MEDIUM] CWE-179 github.com/tektoncd/pipeline: Tekton Pipelines: Unauthorized access and information disclosure via path validation bypass
github.com/tektoncd/pipeline: Tekton Pipelines: Unauthorized access and information disclosure via path validation bypass
A flaw was found in Tekton Pipelines. An attacker can bypass restrictions on where volumes can be mounted by using specially crafted paths that include directory traversal sequences (e.g., `..`). This vulnerability, stemming from an incomplete path validation check, could allow unauthorized access to internal system directories, potentially leading to information disclosure or limited modification of sensitive data.
Package: openshift-builds/openshift-builds-controller-rhel9 (Builds for Red Hat OpenShift) - Fix deferred
Package: openshift-builds/openshift-builds-git-cloner-rhel9 (Builds for Red Hat OpenShift) - Fix deferred
Package: openshift-builds/openshift-builds
GHSA
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
ghsa·2026-04-21
CVE-2026-40923 [MEDIUM] CWE-22 Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
## Summary
A validation bypass in the VolumeMount path restriction allows mounting volumes under restricted `/tekton/` internal paths by using `..` path traversal components. The restriction check uses `strings.HasPrefix` without `filepath.Clean`, so a path like `/tekton/home/../results` passes validation but resolves to `/tekton/results` at runtime.
## Details
Tekton Pipelines restricts VolumeMount paths under `/tekton/` (except `/tekton/home`) to prevent users from interfering with internal execution state. The validation at `pkg/apis/pipeline/v1/container_validation.go` checks mount paths using `strings.HasPrefix` without normalizing the path first:
```go
if strings.HasPrefix(vm.Mount
No detection rules found.
No public exploits indexed.
2026-04-21
Published