<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T11:33:42.328166+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bw27317</id>
    <title>CLEANSTART-2026-BW27317 — Security fix for CVE-2026-40161 applied in: tekton-chains 0.25.2-r1, tekton-chains-fips 0.25.2-r1, tkn-fips 0.44.2-r0</title>
    <updated>2026-10-05T11:33:42.457534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: tekton-chains, CleanStart: tekton-chains-fips, CleanStart: tkn-fips</p>
<p>CVE-2026-40161 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bw27317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319936</id>
    <title>EUVD-2026-319936</title>
    <updated>2026-10-05T11:33:42.457654+00:00</updated>
    <content>EUVD-2026-319936</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40161</id>
    <title>fkie_cve-2026-40161</title>
    <updated>2026-10-05T11:33:42.457691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wjxp-xrpv-xpff</id>
    <title>GHSA-wjxp-xrpv-xpff — Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL</title>
    <updated>2026-10-05T11:33:42.457749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/tektoncd/pipeline</p>
<p>### Summary</p>
<p>The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled `serverURL` when the user omits the `token` parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing `serverURL` to an attacker-controlled endpoint.</p>
<p>### Details</p>
<p>The git resolver's `ResolveAPIGit()` function in `pkg/resolution/resolver/git/resolver.go` constructs an SCM client using the user-supplied `serverURL` and a token obtained via `getAPIToken()`.</p>
<p>When the user provides `serverURL` but omits the `token` parameter:</p>
<p>1. `getSCMTypeAndServerURL()` reads `serverURL` directly from user params (`params[ServerURLParam]`) with no validation against the system-configured URL.</p>
<p>2. `secretRef` is set to `nil` because the user did not provide a token parameter.</p>
<p>3. `getAPIToken(ctx, nil, APISecretNameKey)` is called. It detects `apiSecret == nil`, creates a new `secretCacheKey`, and populates it from the system-configured secret (`conf.APISecretName` / `conf.APISecretNamespace` / `SYSTEM_NAMESPACE`).</p>
<p>4. `clientFunc(scmType, serverURL, string(apiToken))` creates an SCM client pointed at the attacker-controlled URL with the system token. The SCM factory sets the token as an `Authorization` header on the HTTP client.</p>
<p>5. All subsequent API calls (`Contents.Find`, `Git.FindCommit`) carry the system token to the attacker URL.</p>
<p>### Impact</p>
<p>The system Git API token (GitHub PAT…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wjxp-xrpv-xpff"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:24359</id>
    <title>RHSA-2026:24359 — Red Hat Security Advisory: Red Hat OpenShift Builds 1.7.3</title>
    <updated>2026-10-05T11:33:42.457921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:24359"/>
  </entry>
</feed>
