<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:27:48 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GR84261 — Security fixes in tekton-chains-fips 0.24.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gr84261</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains-fips&lt;/p&gt;
&lt;p&gt;Package tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains-fips&lt;/p&gt;
&lt;p&gt;Package tekton-chains-fips version 0.24.0-r1 fixes 26 vulnerabilities: CVE-2026-33818, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gr84261</guid>
    </item>
    <item>
      <title>EUVD-2026-320118</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320118</link>
      <description>EUVD-2026-320118</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320118</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25542</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25542</link>
      <description>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25542</guid>
    </item>
    <item>
      <title>GHSA-rmx9-2pp3-xhcr — Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rmx9-2pp3-xhcr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;hey guys,&lt;/p&gt;
&lt;p&gt;triage contract
this is a first-screen summary; deterministic proof is in the proof bundle (canonical.log/control.log/witness.txt).&lt;/p&gt;
&lt;p&gt;summary
trusted resources verification policies match a resource source string (`refSource.URI`) against `spec.resources[].pattern` using `regexp.MatchString`. in go, `regexp.MatchString` reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. this can cause an unintended policy match and change which verification mode/keys apply.&lt;/p&gt;
&lt;p&gt;pins
- repo: https://github.com/tektoncd/pipeline
- commit: 0133513db03dadb3cb08801d6b0330badcb63830
- callsite: pkg/trustedresources/verify.go:118-137 (getMatchedPolicies)&lt;/p&gt;
&lt;p&gt;severity
MEDIUM (provisional CVSS 5.3–6.5) (signing request tampering)&lt;/p&gt;
&lt;p&gt;repro (canonical)
- command: unzip -q -o poc.zip -d poc &amp;amp;&amp;amp; cd poc/poc-F-TEKTON-REGEX-001 &amp;amp;&amp;amp; make canonical
- expected: cap not reached; canonical does not emit the vulnerability markers.
- actual: cap reached; canonical emits the vulnerability markers.
- canonical markers (mandatory): [CALLSITE\_HIT] + [PROOF\_MARKER]&lt;/p&gt;
&lt;p&gt;negative control
- command: unzip -q -o poc.zip -d poc &amp;amp;&amp;amp; cd poc/poc-F-TEKTON-REGEX-001 &amp;amp;&amp;amp; make control
- expected: cap not reached under the same harness; control emits the control marker and does not emit the vulnerability markers.
- control markers (mandatory): [CAL…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;hey guys,&lt;/p&gt;
&lt;p&gt;triage contract
this is a first-screen summary; deterministic proof is in the proof bundle (canonical.log/control.log/witness.txt).&lt;/p&gt;
&lt;p&gt;summary
trusted resources verification policies match a resource source string (`refSource.URI`) against `spec.resources[].pattern` using `regexp.MatchString`. in go, `regexp.MatchString` reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. this can cause an unintended policy match and change which verification mode/keys apply.&lt;/p&gt;
&lt;p&gt;pins
- repo: https://github.com/tektoncd/pipeline
- commit: 0133513db03dadb3cb08801d6b0330badcb63830
- callsite: pkg/trustedresources/verify.go:118-137 (getMatchedPolicies)&lt;/p&gt;
&lt;p&gt;severity
MEDIUM (provisional CVSS 5.3–6.5) (signing request tampering)&lt;/p&gt;
&lt;p&gt;repro (canonical)
- command: unzip -q -o poc.zip -d poc &amp;amp;&amp;amp; cd poc/poc-F-TEKTON-REGEX-001 &amp;amp;&amp;amp; make canonical
- expected: cap not reached; canonical does not emit the vulnerability markers.
- actual: cap reached; canonical emits the vulnerability markers.
- canonical markers (mandatory): [CALLSITE\_HIT] + [PROOF\_MARKER]&lt;/p&gt;
&lt;p&gt;negative control
- command: unzip -q -o poc.zip -d poc &amp;amp;&amp;amp; cd poc/poc-F-TEKTON-REGEX-001 &amp;amp;&amp;amp; make control
- expected: cap not reached under the same harness; control emits the control marker and does not emit the vulnerability markers.
- control markers (mandatory): [CAL…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rmx9-2pp3-xhcr</guid>
    </item>
  </channel>
</rss>
