<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:49:04 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-BW27317 — Security fix for CVE-2026-40161 applied in: tekton-chains 0.25.2-r1, tekton-chains-fips 0.25.2-r1, tkn-fips 0.44.2-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bw27317</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains, CleanStart: tekton-chains-fips, CleanStart: tkn-fips&lt;/p&gt;
&lt;p&gt;CVE-2026-40161 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains, CleanStart: tekton-chains-fips, CleanStart: tkn-fips&lt;/p&gt;
&lt;p&gt;CVE-2026-40161 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bw27317</guid>
    </item>
    <item>
      <title>EUVD-2026-319936</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319936</link>
      <description>EUVD-2026-319936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319936</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40161</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40161</link>
      <description>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40161</guid>
    </item>
    <item>
      <title>GHSA-wjxp-xrpv-xpff — Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wjxp-xrpv-xpff</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled `serverURL` when the user omits the `token` parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing `serverURL` to an attacker-controlled endpoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The git resolver&amp;#39;s `ResolveAPIGit()` function in `pkg/resolution/resolver/git/resolver.go` constructs an SCM client using the user-supplied `serverURL` and a token obtained via `getAPIToken()`.&lt;/p&gt;
&lt;p&gt;When the user provides `serverURL` but omits the `token` parameter:&lt;/p&gt;
&lt;p&gt;1. `getSCMTypeAndServerURL()` reads `serverURL` directly from user params (`params[ServerURLParam]`) with no validation against the system-configured URL.&lt;/p&gt;
&lt;p&gt;2. `secretRef` is set to `nil` because the user did not provide a token parameter.&lt;/p&gt;
&lt;p&gt;3. `getAPIToken(ctx, nil, APISecretNameKey)` is called. It detects `apiSecret == nil`, creates a new `secretCacheKey`, and populates it from the system-configured secret (`conf.APISecretName` / `conf.APISecretNamespace` / `SYSTEM_NAMESPACE`).&lt;/p&gt;
&lt;p&gt;4. `clientFunc(scmType, serverURL, string(apiToken))` creates an SCM client pointed at the attacker-controlled URL with the system token. The SCM factory sets the token as an `Authorization` header on the HTTP client.&lt;/p&gt;
&lt;p&gt;5. All subsequent API calls (`Contents.Find`, `Git.FindCommit`) carry the system token to the attacker URL.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The system Git API token (GitHub PAT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled `serverURL` when the user omits the `token` parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing `serverURL` to an attacker-controlled endpoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The git resolver&amp;#39;s `ResolveAPIGit()` function in `pkg/resolution/resolver/git/resolver.go` constructs an SCM client using the user-supplied `serverURL` and a token obtained via `getAPIToken()`.&lt;/p&gt;
&lt;p&gt;When the user provides `serverURL` but omits the `token` parameter:&lt;/p&gt;
&lt;p&gt;1. `getSCMTypeAndServerURL()` reads `serverURL` directly from user params (`params[ServerURLParam]`) with no validation against the system-configured URL.&lt;/p&gt;
&lt;p&gt;2. `secretRef` is set to `nil` because the user did not provide a token parameter.&lt;/p&gt;
&lt;p&gt;3. `getAPIToken(ctx, nil, APISecretNameKey)` is called. It detects `apiSecret == nil`, creates a new `secretCacheKey`, and populates it from the system-configured secret (`conf.APISecretName` / `conf.APISecretNamespace` / `SYSTEM_NAMESPACE`).&lt;/p&gt;
&lt;p&gt;4. `clientFunc(scmType, serverURL, string(apiToken))` creates an SCM client pointed at the attacker-controlled URL with the system token. The SCM factory sets the token as an `Authorization` header on the HTTP client.&lt;/p&gt;
&lt;p&gt;5. All subsequent API calls (`Contents.Find`, `Git.FindCommit`) carry the system token to the attacker URL.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The system Git API token (GitHub PAT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wjxp-xrpv-xpff</guid>
    </item>
    <item>
      <title>RHSA-2026:24359 — Red Hat Security Advisory: Red Hat OpenShift Builds 1.7.3</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24359</link>
      <description>&lt;p&gt;crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure of Git API token via user-controlled serverURL github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24359</guid>
    </item>
  </channel>
</rss>
