PT-2026-34001 · Unknown · Tekton Pipelines

·

CVE-2026-25542

·

Published

2026-04-21

·

Updated

2026-07-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tekton Pipelines versions 0.43.0 through 1.11.0
Description Trusted resources verification policies match a resource source string refSource.URI against spec.resources[].pattern using the regexp.MatchString function. Because this function reports a match if the pattern is found anywhere in the string, unanchored patterns can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This may lead to an unintended policy match and alter the applicable verification modes or keys.
Recommendations Update Tekton Pipelines to a version later than 1.11.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25542
GHSA-RMX9-2PP3-XHCR
GO-2026-5630
OPENSUSE-SU-2026:21483-1

Affected Products

Tekton Pipelines