CVE-2026-25542Disclosure(linuxfoundation / tekton_pipelines)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-185

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tekton_pipelines

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
tekton_pipelines

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 204-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25542 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a reso… https://www.cve.org/CVERecord?id=CVE-2026-25542

    Post summary

    The text notes a new CVE in Tekton Pipelines affecting versions 0.43.0 to 1.11.0 but gives no info on exploitation, patches, or technical details.

    00010175
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-25542 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a reso… https://www.cve.org/CVERecord?id=CVE-2026-25542 ----- Traducción: CVE-2026-25542 El … http://infoflow.cloud`

    Post summary

    The snippet merely names CVE-2026-25542, cites the Tekton Pipelines affected range, and links to the CVE record, without providing exploitation details, patches, or confirmation of active use.

    0000026
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationtekton_pipelines-go-

Explore more