PT-2026-34001 · Unknown · Tekton Pipelines
1Seal
+1
·
Published
2026-04-21
·
Updated
2026-05-22
·
CVE-2026-25542
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tekton Pipelines versions 0.43.0 through 1.11.0
Description
Trusted resources verification policies match a resource source string
refSource.URI against spec.resources[].pattern using the regexp.MatchString function. Because this function reports a match if the pattern is found anywhere in the string, unanchored patterns can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This may lead to an unintended policy match and alter the applicable verification modes or keys.Recommendations
Update Tekton Pipelines to a version later than 1.11.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tekton Pipelines