<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:23:50.460542+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ha54107</id>
    <title>Withdrawn: CLEANSTART-2026-HA54107 — Security fixes in tekton-chains 0.25.2-r1</title>
    <updated>2026-10-02T16:23:50.464171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: tekton-chains</p>
<p>Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ha54107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320115</id>
    <title>EUVD-2026-320115</title>
    <updated>2026-10-02T16:23:50.464216+00:00</updated>
    <content>EUVD-2026-320115</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40923</id>
    <title>fkie_cve-2026-40923</title>
    <updated>2026-10-02T16:23:50.464232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path traversal components. The restriction check uses strings.HasPrefix without filepath.Clean, so a path like /tekton/home/../results passes validation but resolves to /tekton/results at runtime. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rx35-6rhx-7858</id>
    <title>GHSA-rx35-6rhx-7858 — Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check</title>
    <updated>2026-10-02T16:23:50.464255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/tektoncd/pipeline</p>
<p>### Summary</p>
<p>A validation bypass in the VolumeMount path restriction allows mounting
volumes under restricted `/tekton/` internal paths by using `..` path
traversal components. The restriction check uses `strings.HasPrefix`
without `filepath.Clean`, so a path like `/tekton/home/../results`
passes validation but resolves to `/tekton/results` at runtime.</p>
<p>### Details</p>
<p>Tekton Pipelines restricts VolumeMount paths under `/tekton/` (except
`/tekton/home`) to prevent users from interfering with internal
execution state. The validation at
`pkg/apis/pipeline/v1/container_validation.go` checks mount paths using
`strings.HasPrefix` without normalizing the path first:</p>
<p>```go
if strings.HasPrefix(vm.MountPath, "/tekton/") &amp;&amp;
    !strings.HasPrefix(vm.MountPath, "/tekton/home") {
    // reject
}
```</p>
<p>Because `/tekton/home` is an allowed prefix, a path like
`/tekton/home/../results` passes both checks. At runtime, the container
runtime resolves `..` and the actual mount point becomes
`/tekton/results`.</p>
<p>The same pattern exists in `pkg/apis/pipeline/v1beta1/task_validation.go`.</p>
<p>### Impact</p>
<p>An authenticated user with Task or TaskRun creation permissions can
mount volumes over internal Tekton paths, potentially:</p>
<p>- Writing fake task results that downstream pipelines trust
- Reading or modifying step scripts before execution
- Interfering with entrypoint coordination state</p>
<p>### Patches</p>
<p>_(to be filled: fixed in versions X.Y.Z)_</p>
<p>### Workarounds</p>
<p>- Use admission controllers (OPA/Gatekeeper, K…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rx35-6rhx-7858"/>
  </entry>
</feed>
