<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:23:14 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-HA54107 — Security fixes in tekton-chains 0.25.2-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ha54107</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains&lt;/p&gt;
&lt;p&gt;Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tekton-chains&lt;/p&gt;
&lt;p&gt;Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ha54107</guid>
    </item>
    <item>
      <title>EUVD-2026-364302</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364302</link>
      <description>EUVD-2026-364302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364302</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40938</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40938</link>
      <description>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver&amp;#39;s revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=&amp;lt;binary&amp;gt;. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver&amp;#39;s revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary git fetch flags such as --upload-pack=&amp;lt;binary&amp;gt;. Combined with the validateRepoURL function explicitly permitting URLs that begin with / (local filesystem paths), a tenant who can submit ResolutionRequest objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The tekton-pipelines-resolvers ServiceAccount holds cluster-wide get/list/watch on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40938</guid>
    </item>
    <item>
      <title>GHSA-94jr-7pqp-xhcq — Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-94jr-7pqp-xhcq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The git resolver&amp;#39;s `revision` parameter is passed directly as a positional argument to `git fetch` without any validation that it does not begin with a `-` character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary `git fetch` flags such as `--upload-pack=&amp;lt;binary&amp;gt;`. Combined with the `validateRepoURL` function explicitly permitting URLs that begin with `/` (local filesystem paths), a tenant who can submit `ResolutionRequest` objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The `tekton-pipelines-resolvers` ServiceAccount holds cluster-wide `get/list/watch` on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause 1 — Unvalidated `revision` parameter passed to `git fetch`&lt;/p&gt;
&lt;p&gt;`pkg/resolution/resolver/git/repository.go:85`:&lt;/p&gt;
&lt;p&gt;```go
// pkg/resolution/resolver/git/repository.go lines 84-96
// &amp;#39;revision&amp;#39; is the raw user-supplied string from the ResolutionRequest param.
// It is passed verbatim as a positional argument to git fetch:
func (repo *repository) checkout(ctx context.Context, revision string) error {
    _, err := repo.execGit(ctx, &amp;#34;fetch&amp;#34;, &amp;#34;origin&amp;#34;, revision, &amp;#34;--depth=1&amp;#34;)
    // When revision == &amp;#34;--upload-pack=/usr/bin/curl&amp;#34;, git parses it as the
    // --upload-pack flag, not as a refspec — executing the binary locally.
    if err != nil {
        return fmt.Errorf(&amp;#34;fetch: %w&amp;#34;, err)
    }
    _, err = repo.exe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/tektoncd/pipeline&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The git resolver&amp;#39;s `revision` parameter is passed directly as a positional argument to `git fetch` without any validation that it does not begin with a `-` character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary `git fetch` flags such as `--upload-pack=&amp;lt;binary&amp;gt;`. Combined with the `validateRepoURL` function explicitly permitting URLs that begin with `/` (local filesystem paths), a tenant who can submit `ResolutionRequest` objects can chain these two behaviors to execute an arbitrary binary on the resolver pod. The `tekton-pipelines-resolvers` ServiceAccount holds cluster-wide `get/list/watch` on all Secrets, so code execution on the resolver pod enables full cluster-wide secret exfiltration.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause 1 — Unvalidated `revision` parameter passed to `git fetch`&lt;/p&gt;
&lt;p&gt;`pkg/resolution/resolver/git/repository.go:85`:&lt;/p&gt;
&lt;p&gt;```go
// pkg/resolution/resolver/git/repository.go lines 84-96
// &amp;#39;revision&amp;#39; is the raw user-supplied string from the ResolutionRequest param.
// It is passed verbatim as a positional argument to git fetch:
func (repo *repository) checkout(ctx context.Context, revision string) error {
    _, err := repo.execGit(ctx, &amp;#34;fetch&amp;#34;, &amp;#34;origin&amp;#34;, revision, &amp;#34;--depth=1&amp;#34;)
    // When revision == &amp;#34;--upload-pack=/usr/bin/curl&amp;#34;, git parses it as the
    // --upload-pack flag, not as a refspec — executing the binary locally.
    if err != nil {
        return fmt.Errorf(&amp;#34;fetch: %w&amp;#34;, err)
    }
    _, err = repo.exe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-94jr-7pqp-xhcq</guid>
    </item>
    <item>
      <title>RHSA-2026:17546 — Red Hat Security Advisory: Red Hat OpenShift Builds 1.8.0</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:17546</link>
      <description>&lt;p&gt;github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:17546</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1550 — Red Hat OpenShift: Schwachstelle ermöglicht Codeausführung und Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1550</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1550</guid>
    </item>
  </channel>
</rss>
