<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:35:19.140703+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bz35157</id>
    <title>CLEANSTART-2026-BZ35157 — Security fix for CVE-2026-33211 applied in: tkn-fips 0.43.0-r4</title>
    <updated>2026-10-02T11:35:19.165493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: tkn-fips</p>
<p>Security vulnerability affects the tkn-fips package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bz35157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364313</id>
    <title>EUVD-2026-364313</title>
    <updated>2026-10-02T11:35:19.165555+00:00</updated>
    <content>EUVD-2026-364313</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33211</id>
    <title>fkie_cve-2026-33211</title>
    <updated>2026-10-02T11:35:19.165572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j5q5-j9gm-2w5c</id>
    <title>GHSA-j5q5-j9gm-2w5c — Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod</title>
    <updated>2026-10-02T11:35:19.165601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/tektoncd/pipeline</p>
<p>### Summary</p>
<p>The Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`.</p>
<p>### Details</p>
<p>The git resolver's `getFileContent()` function in `pkg/resolution/resolver/git/repository.go` constructs a file path by joining the repository clone directory with the user-supplied `pathInRepo` parameter:</p>
<p>```go
fileContents, err := os.ReadFile(filepath.Join(repo.directory, path))
```</p>
<p>The `pathInRepo` parameter is not validated for path traversal sequences. An attacker can supply values like `../../../../etc/passwd` to escape the cloned repository directory and read arbitrary files from the resolver pod's filesystem.</p>
<p>The vulnerability was introduced in commit `318006c4e3a5` which switched the git resolver from the go-git library (using an in-memory filesystem that cannot be escaped) to shelling out to the `git` binary and reading files with `os.ReadFile()` from the real filesystem.</p>
<p>### Impact</p>
<p>**Arbitrary file read** — A namespace-scoped tenant who can create `TaskRuns` or `PipelineRuns` with git resolver parameters can read any file readable by the resolver pod process.</p>
<p>**Credential exfiltration and privilege escalation** — The resolver pod's Ser…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j5q5-j9gm-2w5c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10529-1</id>
    <title>openSUSE-SU-2026:10529-1 — tekton-cli-0.44.1-1.1 on GA media</title>
    <updated>2026-10-02T11:35:19.165659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tekton-cli-0.44.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10529-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10026</id>
    <title>RHSA-2026:10026 — Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.4</title>
    <updated>2026-10-02T11:35:19.165679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10026"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1249</id>
    <title>WID-SEC-W-2026-1249 — Red Hat OpenShift Pipelines: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:35:19.165698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Pipelines ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1249"/>
  </entry>
</feed>
