CVE-2026-40938Disclosure(linuxfoundation / tekton_pipelines)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation tekton_pipelines systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=<binary>. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tekton_pipelines

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
tekton_pipelines

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-26: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-28: 104-2204-2304-2604-28
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-231
Disclosure1
2026-04-262
Disclosure1General1
2026-04-281
Disclosure1
Full discourse5 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40938: CVE-2026-40938: Remote Code Execution via Argument Injection in Tekton Pipelines Git Resolver Tekton Pipelines versions 1.0.0 through 1.11.0 contain a critical argument injection vulnerability in the git resolver component. An attacker... https://cvereports.com/reports/CVE-2026-40938

    Post summary

    A critical argument injection vulnerability (CVE‑2026‑40938) in Tekton Pipelines’ Git Resolver allows remote code execution; the snippet provides technical details but no PoC, exploit code, or patch information.

    0000026
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40938 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to before 1.11.0, the git resolver's revision parameter is passe… https://www.cve.org/CVERecord?id=CVE-2026-40938 ----- Traducción: CVE-2026-40938 Tek… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑40938 affecting Tekton Pipelines, noting a vulnerability in the git resolver’s revision parameter across certain versions, without mentioning PoC, exploit, or patch details.

    0000033
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40938 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to before 1.11.0, the git resolver's revision parameter is passe… https://www.cve.org/CVERecord?id=CVE-2026-40938

    Post summary

    The snippet references CVE-2026-40938, noting the affected Tekton Pipelines versions and a flaw involving the git resolver's revision parameter, but provides no PoC, exploit, or mitigation details.

    00000200
    57.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Git argument injection vulnerability (CVE-2026-40938) has been identified in `Tekton Pipeline`'s Git Resolver, enabling potential RCE. Review pipeline configurations and sanitize inputs. #Tekton #RCE #DevSecOps https://www.pulsepatch.io/posts/cve-2026-40938-tekton-pipeline-git-resolver-rce

    Post summary

    The post announces the discovery of CVE‑2026‑40938 in Tekton Pipeline’s Git Resolver, highlighting a potential RCE due to Git argument injection, without providing a PoC, exploit code, patch, or evidence of active exploitation.

    0000052
    12 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A `Tekton Pipeline` vulnerability (CVE-2026-40938) allows `Git Resolver` argument injection, enabling RCE. Review pipeline configurations. #Tekton #CI_CD #RCE https://www.pulsepatch.io/posts/cve-2026-40938-tekton-pipeline-git-resolver-rce

    Post summary

    CVE-2026-40938 is a Git Resolver argument injection flaw in Tekton Pipeline that permits remote code execution; administrators should review pipeline configurations to mitigate the risk.

    0000053
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationtekton_pipelines-go-

Explore more