CVE-2026-25542None▾ SunlitTekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
github.com/tektoncd/pipeline >= 1.10.0, < 1.11.1Upgrade to a patched release:
github.com/tektoncd/pipeline 1.11.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40161NoneTekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
CVE-2026-40923NoneTekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
CVE-2026-40924NoneTekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
CVE-2026-33022NoneTekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories