<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:10:32 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-FN18256 — Security fix for CVE-2026-33022 applied in: tekton-chains-fips 0.24.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fn18256</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the tekton-chains-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the tekton-chains-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fn18256</guid>
    </item>
    <item>
      <title>EUVD-2026-276709</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276709</link>
      <description>EUVD-2026-276709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276709</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33022</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33022</link>
      <description>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerability in that allows any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. The crash occurs because GenerateDeterministicNameFromSpec produces a name exceeding the 63-character DNS-1123 label limit, and its truncation logic panics on a [-1] slice bound since the generated name contains no spaces. Once crashed, the controller enters a CrashLoopBackOff on restart (as it re-reconciles the offending resource), blocking all CI/CD reconciliation until the resource is manually deleted. Built-in resolvers (git, cluster, bundles, hub) are unaffected due to their short names, but any custom resolver name triggers the bug. The fix truncates the resolver-name prefix instead of the full string, preserving the hash suffix for determinism and uniqueness. This issue has been patched in versions 1.0.1, 1.3.3, 1.6.1, 1.9.2 and 1.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerability in that allows any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. The crash occurs because GenerateDeterministicNameFromSpec produces a name exceeding the 63-character DNS-1123 label limit, and its truncation logic panics on a [-1] slice bound since the generated name contains no spaces. Once crashed, the controller enters a CrashLoopBackOff on restart (as it re-reconciles the offending resource), blocking all CI/CD reconciliation until the resource is manually deleted. Built-in resolvers (git, cluster, bundles, hub) are unaffected due to their short names, but any custom resolver name triggers the bug. The fix truncates the resolver-name prefix instead of the full string, preserving the hash suffix for determinism and uniqueness. This issue has been patched in versions 1.0.1, 1.3.3, 1.6.1, 1.9.2 and 1.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33022</guid>
    </item>
    <item>
      <title>GHSA-cv4x-93xx-wgfj — Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cv4x-93xx-wgfj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user with permission to create or update a TaskRun or PipelineRun can crash the Tekton Pipelines controller by setting `.spec.taskRef.resolver` (or `.spec.pipelineRef.resolver`) to a string of 31 characters or more, causing a denial of service for all reconciliation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The controller panics in `GenerateDeterministicNameFromSpec` when building a deterministic `ResolutionRequest` name. The generated name has the format `{resolver}-{hash}` and, when the resolver name is long enough, the result exceeds the DNS-1123 label limit of 63 characters.&lt;/p&gt;
&lt;p&gt;The truncation logic attempts to find a word boundary using `strings.LastIndex(name, &amp;#34; &amp;#34;)`. Since the generated name never contains spaces (it is composed of the resolver name, a dash, and a hex-encoded hash), `LastIndex` returns `-1`, which is then used as a slice bound:&lt;/p&gt;
&lt;p&gt;```go
return name[:strings.LastIndex(name[:maxLength], &amp;#34; &amp;#34;)], nil
// strings.LastIndex returns -1 → panic: slice bounds out of range [:-1]
```&lt;/p&gt;
&lt;p&gt;The panic crashes the controller. Because the offending TaskRun or PipelineRun is re-reconciled on restart, the controller enters a `CrashLoopBackOff`, blocking all TaskRun and PipelineRun reconciliation cluster-wide until the offending resource is manually deleted.&lt;/p&gt;
&lt;p&gt;Built-in resolvers use short names (`git`, `cluster`, `bundles`, `hub`) and are not affected under normal usage. The vulnerability is exploitable by any user who can create TaskRuns or PipelineRuns with a custom resolver name.&lt;/p&gt;
&lt;p&gt;### Impact…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user with permission to create or update a TaskRun or PipelineRun can crash the Tekton Pipelines controller by setting `.spec.taskRef.resolver` (or `.spec.pipelineRef.resolver`) to a string of 31 characters or more, causing a denial of service for all reconciliation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The controller panics in `GenerateDeterministicNameFromSpec` when building a deterministic `ResolutionRequest` name. The generated name has the format `{resolver}-{hash}` and, when the resolver name is long enough, the result exceeds the DNS-1123 label limit of 63 characters.&lt;/p&gt;
&lt;p&gt;The truncation logic attempts to find a word boundary using `strings.LastIndex(name, &amp;#34; &amp;#34;)`. Since the generated name never contains spaces (it is composed of the resolver name, a dash, and a hex-encoded hash), `LastIndex` returns `-1`, which is then used as a slice bound:&lt;/p&gt;
&lt;p&gt;```go
return name[:strings.LastIndex(name[:maxLength], &amp;#34; &amp;#34;)], nil
// strings.LastIndex returns -1 → panic: slice bounds out of range [:-1]
```&lt;/p&gt;
&lt;p&gt;The panic crashes the controller. Because the offending TaskRun or PipelineRun is re-reconciled on restart, the controller enters a `CrashLoopBackOff`, blocking all TaskRun and PipelineRun reconciliation cluster-wide until the offending resource is manually deleted.&lt;/p&gt;
&lt;p&gt;Built-in resolvers use short names (`git`, `cluster`, `bundles`, `hub`) and are not affected under normal usage. The vulnerability is exploitable by any user who can create TaskRuns or PipelineRuns with a custom resolver name.&lt;/p&gt;
&lt;p&gt;### Impact…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cv4x-93xx-wgfj</guid>
    </item>
    <item>
      <title>RHSA-2026:10026 — Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.4</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10026</link>
      <description>&lt;p&gt;github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10026</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1249 — Red Hat OpenShift Pipelines: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1249</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Pipelines ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Pipelines ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1249</guid>
    </item>
  </channel>
</rss>
