CVE-2026-54167High· 8.2▾ TwilightPipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/openshift-pipelines/pipelines-as-code >= 0.43.0, < 0.48.0github.com/openshift-pipelines/pipelines-as-code >= 0.40.0, < 0.42.1github.com/openshift-pipelines/pipelines-as-code >= 0.38.0, < 0.39.6github.com/openshift-pipelines/pipelines-as-code < 0.37.8Patched in:
github.com/openshift-pipelines/pipelines-as-code 0.48.0github.com/openshift-pipelines/pipelines-as-code 0.42.1github.com/openshift-pipelines/pipelines-as-code 0.39.6github.com/openshift-pipelines/pipelines-as-code 0.37.8Source: https://github.com/advisories/GHSA-f5f4-3hh4-f54m
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2026-71576High· 8.5A flaw was found in multicluster-global-hub
CVE-2026-63127High· 8.2RMCP is an official Rust SDK for the Model Context Protocol
CVE-2026-19941Medium· 5.9An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…
CVE-2026-77955Medium· 4.4In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…
CVE-2026-45057Medium· 4.9matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk