tektoncd has 7 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 7.3 (high). None have a confirmed exploitation report. Most affected products: github.com/tektoncd/pipeline (5), pipelines-as-code (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Products
- github.com/tektoncd/pipeline 5
- pipelines-as-code 2
Worst active — by depth score
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories45CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories36CVE-2026-40924NoneTekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline3CVE-2026-40923NoneTekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline3CVE-2026-40161NoneTekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline3
tektoncd vulnerabilities
CVEs affecting tektoncd, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …
CVE-2026-40161NoneTekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
CVE-2026-40923NoneTekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
CVE-2026-25542NoneTekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
CVE-2026-40924NoneTekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
CVE-2026-33022NoneTekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline