CVE-2026-40924
published 2026-04-21CVE-2026-40924: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.32%
25.0th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HTTP resolver can point it at an attacker-controlled HTTP server that returns a very large response body within the 1-minute timeout window, causing the tekton-pipelines-resolvers pod to be OOM-killed by Kubernetes. Because all resolver types (Git, Hub, Bundle, Cluster, HTTP) run in the same pod, crashing this pod denies resolution service to the entire cluster. Repeated exploitation causes a sustained crash loop. The same vulnerable code path is reached by both the deprecated pkg/resolution/resolver/http and the current pkg/remoteresolution/resolver/http implementations. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | kubevirt-ssp-operator-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-create-datavolume-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-disk-virt-customize-rhel9 | — | — |
| container-native-virtualization | kubevirt-template-validator-rhel9 | — | — |
| github.com | tektoncd_pipeline | >= 0 < 1.11.1 | 1.11.1 |
| linux | linux_kernel | >= 6.7.0 < 6.18.6 | 6.18.6 |
| linuxfoundation | tekton_pipelines | < 1.11.1 | 1.11.1 |
| openshift-builds | openshift-builds-controller-rhel9 | — | — |
| openshift-builds | openshift-builds-git-cloner-rhel9 | — | — |
| openshift-builds | openshift-builds-image-bundler-rhel9 | — | — |
| openshift-builds | openshift-builds-image-processing-rhel9 | — | — |
| openshift-builds | openshift-builds-rhel9-operator | — | — |
| openshift-builds | openshift-builds-waiters-rhel9 | — | — |
| openshift-builds | openshift-builds-webhook-rhel9 | — | — |
| openshift-lightspeed | openshift-mcp-server-rhel9 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel8 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel9 | — | — |
| openshift-pipelines | pipelines-controller-rhel8 | — | — |
| openshift-pipelines | pipelines-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-entrypoint-rhel8 | — | — |
| openshift-pipelines | pipelines-entrypoint-rhel9 | — | — |
| openshift-pipelines | pipelines-events-rhel8 | — | — |
| openshift-pipelines | pipelines-events-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via large HTTP response body
vendor_redhat·2026-04-21·CVSS 6.5
CVE-2026-40924 [MEDIUM] CWE-770 github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via large HTTP response body
github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via large HTTP response body
A flaw was found in Tekton Pipelines. A local user with specific permissions to create TaskRuns or PipelineRuns can exploit this by directing the HTTP resolver to an attacker-controlled server. This server can return a very large response body, leading to the tekton-pipelines-resolvers pod consuming excessive memory and being terminated by Kubernetes. Repeated exploitation of this resource exhaustion vulnerability can cause a sustained denial of service for the entire cluster's resolution services.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability
Red Hat
kernel: idpf: fix error handling in the init_task on load
vendor_redhat·2026-01-31·CVSS 5.5
CVE-2026-23017 [MEDIUM] CWE-476 kernel: idpf: fix error handling in the init_task on load
kernel: idpf: fix error handling in the init_task on load
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix error handling in the init_task on load
If the init_task fails during a driver load, we end up without vports and
netdevs, effectively failing the entire process. In that state a
subsequent reset will result in a crash as the service task attempts to
access uninitialized resources. Following trace is from an error in the
init_task where the CREATE_VPORT (op 501) is rejected by the FW:
[40922.763136] idpf 0000:83:00.0: Device HW Reset initiated
[40924.449797] idpf 0000:83:00.0: Transaction failed (op 501)
[40958.148190] idpf 0000:83:00.0: HW reset detected
[40958.161202] BUG: kernel NULL pointer dereference, address: 00000000000000a8
...
[40958.168094] Wor
GHSA
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
ghsa·2026-04-21
CVE-2026-40924 [MEDIUM] CWE-400 Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
## Summary
The HTTP resolver's `FetchHttpResource` function calls `io.ReadAll(resp.Body)` with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HTTP resolver can point it at an attacker-controlled HTTP server that returns a very large response body within the 1-minute timeout window, causing the `tekton-pipelines-resolvers` pod to be OOM-killed by Kubernetes. Because all resolver types (Git, Hub, Bundle, Cluster, HTTP) run in the same pod, crashing this pod denies resolution service to the entire cluster. Repeated exploitation causes a sustained crash loop. The same vulnerable code path is reached by both the deprecated
OSV
idpf: fix error handling in the init_task on load
osv·2026-01-31·CVSS 5.5
CVE-2026-23017 idpf: fix error handling in the init_task on load
idpf: fix error handling in the init_task on load
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix error handling in the init_task on load
If the init_task fails during a driver load, we end up without vports and
netdevs, effectively failing the entire process. In that state a
subsequent reset will result in a crash as the service task attempts to
access uninitialized resources. Following trace is from an error in the
init_task where the CREATE_VPORT (op 501) is rejected by the FW:
[40922.763136] idpf 0000:83:00.0: Device HW Reset initiated
[40924.449797] idpf 0000:83:00.0: Transaction failed (op 501)
[40958.148190] idpf 0000:83:00.0: HW reset detected
[40958.161202] BUG: kernel NULL pointer dereference, address: 00000000000000a8
...
[40958.168094] Workqueu
No detection rules found.
No public exploits indexed.
2026-04-21
Published