CVE-2026-40938
published 2026-04-21CVE-2026-40938: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2…
PriorityP261high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
EPSS
0.90%
58.1th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | kubevirt-tekton-tasks-create-datavolume-rhel9 | — | — |
| container-native-virtualization | kubevirt-tekton-tasks-disk-virt-customize-rhel9 | — | — |
| github.com | tektoncd_pipeline | >= 1.0.0 < 1.11.1 | 1.11.1 |
| linuxfoundation | tekton_pipelines | >= 1.0.0 < 1.11.0 | 1.11.0 |
| openshift-builds | openshift-builds-controller-rhel9 | — | — |
| openshift-builds | openshift-builds-git-cloner-rhel9 | — | — |
| openshift-builds | openshift-builds-image-bundler-rhel9 | — | — |
| openshift-builds | openshift-builds-image-processing-rhel9 | — | — |
| openshift-builds | openshift-builds-rhel9-operator | — | — |
| openshift-builds | openshift-builds-waiters-rhel9 | — | — |
| openshift-builds | openshift-builds-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-chains-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-cli-tkn-rhel9 | — | — |
| openshift-pipelines | pipelines-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-entrypoint-rhel9 | — | — |
| openshift-pipelines | pipelines-events-rhel9 | — | — |
| openshift-pipelines | pipelines-git-init-rhel9 | — | — |
| openshift-pipelines | pipelines-hub-api-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-controller-rhel9 | — | — |
| openshift-pipelines | pipelines-manual-approval-gate-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-nop-rhel9 | — | — |
| openshift-pipelines | pipelines-opc-rhel9 | — | — |
| openshift-pipelines | pipelines-operator-proxy-rhel9 | — | — |
| openshift-pipelines | pipelines-operator-webhook-rhel9 | — | — |
| openshift-pipelines | pipelines-pipelines-as-code-cli-rhel9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The git resolver's `revision` parameter is passed directly as a positional argument to `git fetch` without validation; monitor for revision values beginning with `-` (e.g., `--upload-pack=`) in ResolutionRequest objects submitted to Tekton Pipelines. ↗
- →Monitor ResolutionRequest objects where the repository URL begins with `/` (local filesystem path), which combined with a malicious revision parameter enables arbitrary binary execution on the resolver pod. ↗
- →Alert on any unexpected process execution or outbound secret access originating from the `tekton-pipelines-resolvers` ServiceAccount, which holds cluster-wide get/list/watch on all Secrets. ↗
- →Audit ResolutionRequest submissions by authenticated users for revision parameters containing flag-injection patterns (strings starting with `-`) as an indicator of exploitation attempts. ↗
- →Investigate resolver pod process trees for execution of unexpected binaries, particularly those loaded from local filesystem paths, as exploitation requires a valid git repository at a predictable path already in the resolver pod. ↗
- ·Vulnerability affects Tekton Pipelines versions 1.0.0 through before 1.11.1; fixed versions are 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1. Verify deployed version of the git resolver component. ↗
- ·No mitigation is available from Red Hat that meets their deployment criteria; patching to a fixed version is the only remediation. ↗
- ·Exploitation complexity is high: the attacker must know an existing valid git repository at a predictable path in the resolver pod, or a default URL configuration pointing to a local filesystem path. ↗
- ·Successful exploitation may also enable privilege escalation or lateral movement if kubeconfig files are present in exfiltrated secrets. ↗
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
tektoncd pipeline up to 1.11.0 validateRepoURL argument injection (GHSA-94jr-7pqp-xhcq / WID-SEC-2026-1550)
vuldb·2026-05-16·CVSS 8.5
CVE-2026-40938 [HIGH] tektoncd pipeline up to 1.11.0 validateRepoURL argument injection (GHSA-94jr-7pqp-xhcq / WID-SEC-2026-1550)
A vulnerability was found in tektoncd pipeline up to 1.11.0. It has been declared as critical. Affected is the function validateRepoURL. Such manipulation leads to argument injection.
This vulnerability is uniquely identified as CVE-2026-40938. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
ghsa·2026-04-21
CVE-2026-40938 [HIGH] CWE-88 Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
## Summary
The git resolver's `revision` parameter is passed directly as a positional argument to `git fetch` without any validation that it does not begin with a `-` character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary `git fetch` flags such as `--upload-pack=`. Combined with the `validateRepoURL` function explicitly permitting URLs that begin with `/` (local filesystem paths), a tenant who can submit `ResolutionRequest` objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The `tekton-pipelines-resolvers` ServiceAccount holds cluster-wide `get/list/watch` on all Secrets, so code execution on the r
Red Hat
github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands
vendor_redhat·2026-04-21·CVSS 7.5
CVE-2026-40938 [HIGH] CWE-88 github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands
github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands
A flaw was found in Tekton Pipelines, a system for declaring continuous integration/continuous delivery (CI/CD) pipelines. An authenticated user, able to submit `ResolutionRequest` objects, can exploit a vulnerability by injecting malicious commands into the git resolver's revision parameter. This allows for the execution of unauthorized programs on the resolver pod. Successful exploitation can lead to the exfiltration of all cluster-wide secrets, resulting in significant information disclosure.
Statement: This Important flaw in Tekton Pipelines allows an authenticated user to achieve arbitrary code execution on the resolver pod by injecting malicious commands into
No detection rules found.
No public exploits indexed.
https://github.com/tektoncd/pipeline/releases/tag/v1.11.1https://github.com/tektoncd/pipeline/security/advisories/GHSA-94jr-7pqp-xhcqhttps://access.redhat.com/errata/RHSA-2026:17546https://access.redhat.com/errata/RHSA-2026:24359https://access.redhat.com/errata/RHSA-2026:24484https://access.redhat.com/errata/RHSA-2026:26519https://access.redhat.com/errata/RHSA-2026:26538https://access.redhat.com/security/cve/CVE-2026-40938https://bugzilla.redhat.com/show_bug.cgi?id=2460292https://github.com/tektoncd/pipeline/security/advisories/GHSA-94jr-7pqp-xhcqhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40938.json
2026-04-21
Published