CVE-2026-33211

Aliases:GHSA-j5q5-j9gm-2w5cGO-2026-4761CGA-2gj3-mh9c-hx37CGA-62p5-59q3-h7j6CGA-65w9-4wp8-78jvCGA-66vm-wrq3-82crCGA-6jrq-frjp-hh9rCGA-9vcr-x38f-3582CGA-2gpq-4p7h-2hg8CGA-2h68-p55q-3xgcCGA-33xr-4h7j-p7vvCGA-3h82-g2ff-426pCGA-3p3j-cj54-7ww6CGA-3phx-w389-mrp5CGA-3q39-gm63-7mpxCGA-3r57-2765-fx8gCGA-3r5f-r4x6-c4p8CGA-3rqq-hf4c-fpwgCGA-3rxx-fwqq-j5rcCGA-456q-g9qr-c59rCGA-4579-63fh-69vwCGA-48x4-9c7c-j334CGA-4ccf-wrrc-pp6xCGA-4rfq-6r2g-qmc5CGA-52fj-h4cg-9mgxCGA-56jc-fx3q-6q72CGA-5g64-7g48-36m7CGA-5w46-7xcv-hhqqCGA-62gr-5mfv-r99jCGA-646x-6jwh-86h5CGA-64r6-fwm9-r274CGA-66j2-7w99-c5jwCGA-66w9-w7m4-c823CGA-679r-r67c-39vrCGA-6g86-3x7r-5v9hCGA-6hh8-6qvr-88hfCGA-6hr8-8v65-5pr2CGA-76rf-g7xr-w299CGA-7fc2-fmx2-72mvCGA-7g45-rfx3-qvjqCGA-7g57-w5hp-wfc5CGA-7j3m-hq6g-mfp6CGA-7q6f-7gjm-9465CGA-7qwj-gxr5-frcpCGA-7rvj-q8j7-j335CGA-7wf2-cp9v-cf68CGA-82hq-m3vv-cq7cCGA-876f-cmw5-92rqCGA-8jrj-h238-wwvcCGA-8pfp-whqv-c6xxCGA-8q3f-p99x-6fwqCGA-8r4p-vr7h-frj2CGA-8x5h-pjhv-7rp4CGA-936r-xqc3-pjhjCGA-94xr-mcwf-5x57CGA-96m8-h969-5xh3CGA-9ccm-7g8v-3x6mCGA-9cqj-hwgx-pj79CGA-9cwq-8j4v-ggjhCGA-9f5w-ggxv-x8qqCGA-c28v-xmx7-pp79CGA-c3gx-8m4q-rcwjCGA-c455-vvh9-xxm9CGA-c4ph-w42f-w653CGA-c6wx-q92h-rh5qCGA-c88m-p2r5-7jv7CGA-cmqj-qjxm-88cxCGA-f4gx-j46p-h9p4CGA-f5qr-4x98-v8q4CGA-f956-rhp9-cg6rCGA-fcrc-p3fx-q938CGA-fqqm-jhh8-32w7CGA-fx9r-3f3m-qgm6CGA-g89p-8765-38c6CGA-gf3m-rvqh-g2xgCGA-gf9f-jvq8-j5v7CGA-gg2p-hq23-pj5rCGA-gpgr-rxg5-qrj3CGA-gpwc-mpx7-7q2wCGA-gr6j-pv7x-wm87CGA-hqrp-p4f6-hr8rCGA-hv78-792c-84xrCGA-j37q-ccjm-pmwfCGA-j3q5-w39g-q3mxCGA-j9x2-3jvr-44rgCGA-jh7j-wvvg-v3q8CGA-jq3r-8364-ww9qCGA-jx93-qqw4-6xhxCGA-m6r9-7x88-4f8hCGA-m96r-jm38-g74vCGA-m9j8-p8hw-q99xCGA-mhmq-7f6x-4j58CGA-mv3q-98m3-g7mwCGA-mx2j-f299-62hwCGA-mx75-p8q2-mwc4CGA-pcr6-cj73-gfmpCGA-pcvh-wh4g-8fc3CGA-pmpw-2vq7-qm3vCGA-ppxj-f5x3-47h6CGA-pv2v-xx39-g7fqCGA-q9w9-fcqq-4c5mCGA-r2hq-758g-98w5CGA-r88h-7667-4h9cCGA-rm33-9mmq-ff2pCGA-rmqx-533r-6m89CGA-rrx4-m8hj-g4vpCGA-rvp7-fhcw-96c4CGA-rw95-f8v5-xpjwCGA-vc6x-hjqm-7vqfCGA-w45v-p3gm-r28wCGA-w6mg-fv8j-vf72CGA-wcj2-6x66-7gjpCGA-wf53-8p47-vmprCGA-wpwj-685m-mpm3CGA-wq89-x4vc-x4f6CGA-wv6x-8j4q-4w78CGA-wwr5-crm6-wxfvCGA-x5wf-mxhg-vg8jCGA-x8xg-mm8r-5hg8CGA-xg99-pwfr-94qxCGA-xhh8-gx9h-9qqxCGA-xq3w-w7hq-v8vvCGA-xq7c-fhqf-5c6mCGA-xwmg-q3ff-fjw8
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 23 Mar 2026, 23:55
Last modified:07 Sept 2026, 12:05

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.6 CRITICAL
v3.1 (cve.org)
EPSS Score
0.57% LOW
1% probability +0.09%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Mar 2026, 23:55
Published
Vulnerability first disclosed
07 Sept 2026, 12:05
Last Modified
Vulnerability information updated

Description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.

CVSS Metrics

  • v3.1CRITICALScore: 9.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.57% Percentile: 46%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardtekton-chains

    < 0.26.2-r4

  • chainguardtekton-chains-fips

    < 0.26.2-r5

  • chainguardtekton-pipelines-controller-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-controller-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-controller-1.5

    all

  • chainguardtekton-pipelines-controller-1.7

    all

  • chainguardtekton-pipelines-controller-1.9

    < 1.9.2-r0

  • chainguardtekton-pipelines-controller-fips-1.4

    all

  • chainguardtekton-pipelines-controller-fips-1.5

    all

  • chainguardtekton-pipelines-controller-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-entrypoint-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-entrypoint-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-entrypoint-1.5

    all

  • chainguardtekton-pipelines-entrypoint-1.7

    all

  • chainguardtekton-pipelines-entrypoint-1.9

    < 1.9.2-r0

  • chainguardtekton-pipelines-entrypoint-fips-1.4

    all

  • chainguardtekton-pipelines-entrypoint-fips-1.5

    all

  • chainguardtekton-pipelines-entrypoint-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-events-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-events-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-events-1.5

    all

  • chainguardtekton-pipelines-events-1.7

    all

  • chainguardtekton-pipelines-events-fips-1.4

    all

  • chainguardtekton-pipelines-events-fips-1.5

    all

  • chainguardtekton-pipelines-events-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-nop-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-nop-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-nop-1.5

    all

  • chainguardtekton-pipelines-nop-1.7

    all

  • chainguardtekton-pipelines-nop-fips-1.4

    all

  • chainguardtekton-pipelines-nop-fips-1.5

    all

  • chainguardtekton-pipelines-nop-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-resolvers-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-resolvers-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-resolvers-1.5

    all

  • chainguardtekton-pipelines-resolvers-1.7

    all

  • chainguardtekton-pipelines-resolvers-1.9

    < 1.9.2-r0

  • chainguardtekton-pipelines-resolvers-fips-1.4

    all

  • chainguardtekton-pipelines-resolvers-fips-1.5

    all

  • chainguardtekton-pipelines-resolvers-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-sidecarlogresults-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-sidecarlogresults-1.4

    < 1.4.0-r19

  • chainguardtekton-pipelines-sidecarlogresults-1.5

    all

  • chainguardtekton-pipelines-sidecarlogresults-1.7

    all

  • chainguardtekton-pipelines-sidecarlogresults-1.9

    < 1.9.2-r0

  • chainguardtekton-pipelines-sidecarlogresults-fips-1.4

    all

  • chainguardtekton-pipelines-sidecarlogresults-fips-1.5

    all

  • chainguardtekton-pipelines-sidecarlogresults-fips-1.7

    < 1.7.0-r14

  • chainguardtekton-pipelines-webhook-1.3

    < 1.3.3-r0

  • chainguardtekton-pipelines-webhook-1.4

    < 1.4.0-r19

Showing first 50 affected entries in server-rendered view.

References (24)