CVE-2026-40924Disclosure(linuxfoundation / tekton_pipelines)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation tekton_pipelines systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HTTP resolver can point it at an attacker-controlled HTTP server that returns a very large response body within the 1-minute timeout window, causing the tekton-pipelines-resolvers pod to be OOM-killed by Kubernetes. Because all resolver types (Git, Hub, Bundle, Cluster, HTTP) run in the same pod, crashing this pod denies resolution service to the entire cluster. Repeated exploitation causes a sustained crash loop. The same vulnerable code path is reached by both the deprecated pkg/resolution/resolver/http and the current pkg/remoteresolution/resolver/http implementations. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tekton_pipelines

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
tekton_pipelines

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-26: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-28: 104-2604-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-262
Disclosure1General1
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40924: CVE-2026-40924: Uncontrolled Resource Consumption in Tekton Pipelines HTTP Resolver An uncontrolled resource consumption vulnerability exists in the HTTP resolver component of Tekton Pipelines prior to version 1.11.1. The flaw allows a... https://cvereports.com/reports/CVE-2026-40924

    Post summary

    The post delivers a brief disclosure of an uncontrolled resource consumption flaw in Tekton Pipelines’ HTTP resolver, noting it existed before version 1.11.1 without providing PoCs, exploit tools, or evidence of active exploitation.

    0000022
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40924 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, the HTTP resolver's FetchHttpResource function calls http://io.Re… https://www.cve.org/CVERecord?id=CVE-2026-40924 ----- Traducción: … http://infoflow.cloud`

    Post summary

    The tweet confirms that CVE‑2026‑40924 existed in Tekton Pipelines before version 1.11.1, describing a flaw in the FetchHttpResource HTTP resolver, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000036
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40924 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, the HTTP resolver's FetchHttpResource function calls http://io.Re… https://www.cve.org/CVERecord?id=CVE-2026-40924

    Post summary

    The post briefly references CVE‑2026‑40924 in Tekton Pipelines, noting a flaw in the HTTP resolver before version 1.11.1, but it offers no PoC, exploit, or patch details.

    00000195
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationtekton_pipelines-go-

Explore more