tekton_pipelines vulnerabilities
CVEs whose affected-version data names the tekton_pipelines package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-40938High· 7.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly a…
▾ Twilightlinuxfoundation · tekton_pipelinesEPSS 0.79%via NVD
CVE-2026-33211Critical· 9.6Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path tr…
▾ Midnightlinuxfoundation · tekton_pipelinesEPSS 0.57%via NVD