cbcvebase.
CVE-2026-40938
published 2026-04-21

CVE-2026-40938: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2…

PriorityP261high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
EPSS
0.90%
58.1th percentile
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
container-native-virtualizationkubevirt-tekton-tasks-create-datavolume-rhel9——
container-native-virtualizationkubevirt-tekton-tasks-disk-virt-customize-rhel9——
github.comtektoncd_pipeline>= 1.0.0 < 1.11.11.11.1
linuxfoundationtekton_pipelines>= 1.0.0 < 1.11.01.11.0
openshift-buildsopenshift-builds-controller-rhel9——
openshift-buildsopenshift-builds-git-cloner-rhel9——
openshift-buildsopenshift-builds-image-bundler-rhel9——
openshift-buildsopenshift-builds-image-processing-rhel9——
openshift-buildsopenshift-builds-rhel9-operator——
openshift-buildsopenshift-builds-waiters-rhel9——
openshift-buildsopenshift-builds-webhook-rhel9——
openshift-pipelinespipelines-chains-controller-rhel9——
openshift-pipelinespipelines-cli-tkn-rhel9——
openshift-pipelinespipelines-controller-rhel9——
openshift-pipelinespipelines-entrypoint-rhel9——
openshift-pipelinespipelines-events-rhel9——
openshift-pipelinespipelines-git-init-rhel9——
openshift-pipelinespipelines-hub-api-rhel9——
openshift-pipelinespipelines-manual-approval-gate-controller-rhel9——
openshift-pipelinespipelines-manual-approval-gate-webhook-rhel9——
openshift-pipelinespipelines-nop-rhel9——
openshift-pipelinespipelines-opc-rhel9——
openshift-pipelinespipelines-operator-proxy-rhel9——
openshift-pipelinespipelines-operator-webhook-rhel9——
openshift-pipelinespipelines-pipelines-as-code-cli-rhel9——

Detection & IOCsextracted from sources · hover to see the quote

  • →The git resolver's `revision` parameter is passed directly as a positional argument to `git fetch` without validation; monitor for revision values beginning with `-` (e.g., `--upload-pack=`) in ResolutionRequest objects submitted to Tekton Pipelines. ↗
  • →Monitor ResolutionRequest objects where the repository URL begins with `/` (local filesystem path), which combined with a malicious revision parameter enables arbitrary binary execution on the resolver pod. ↗
  • →Alert on any unexpected process execution or outbound secret access originating from the `tekton-pipelines-resolvers` ServiceAccount, which holds cluster-wide get/list/watch on all Secrets. ↗
  • →Audit ResolutionRequest submissions by authenticated users for revision parameters containing flag-injection patterns (strings starting with `-`) as an indicator of exploitation attempts. ↗
  • →Investigate resolver pod process trees for execution of unexpected binaries, particularly those loaded from local filesystem paths, as exploitation requires a valid git repository at a predictable path already in the resolver pod. ↗
  • ·Vulnerability affects Tekton Pipelines versions 1.0.0 through before 1.11.1; fixed versions are 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1. Verify deployed version of the git resolver component. ↗
  • ·No mitigation is available from Red Hat that meets their deployment criteria; patching to a fixed version is the only remediation. ↗
  • ·Exploitation complexity is high: the attacker must know an existing valid git repository at a predictable path in the resolver pod, or a default URL configuration pointing to a local filesystem path. ↗
  • ·Successful exploitation may also enable privilege escalation or lateral movement if kubeconfig files are present in exfiltrated secrets. ↗

CVSS provenance

nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.