CVE-2026-33211

Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.1

criticalEPSS 0.6%

Description

A flaw was found in Tekton Pipelines, specifically in the Tekton Pipelines git resolver. A tenant with permissions to create ResolutionRequests can exploit a path traversal vulnerability via the `pathInRepo` parameter. This allows the tenant to read arbitrary files from the resolver pod's filesystem, leading to information disclosure, including sensitive ServiceAccount tokens. The contents of these files are returned in a base64-encoded format.

Metrics

Severity
critical
no public PoC known
9.6
Source: nvd-v3
45.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-03-30 12:14 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-07 13:18 UTC· security-advisories@github.com
    • Reference: https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c
    • Reference: https://github.com/tektoncd/pipeline/commit/318006c4e3a5
    • Reference: https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd
    • Reference: https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae
  2. CVE Modified2026-09-07 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33211.json">CVE-2026-33211</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:10026
    • Reference: https://access.redhat.com/errata/RHSA-2026:10066
    • Reference: https://access.redhat.com/errata/RHSA-2026:10125
  3. CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48)Red Hat OpenShift Builds 1.6.4, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Pipelines 1.2 (+48)
  4. CVE Modified2026-08-03 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48)Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Pipelines 1.2 (+48)
  5. CVE Modified2026-07-27 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Pipelines 1.2 (+48)Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • axios

    axios1.0.0 – 1.13.5

  • axios

    axios0.30.3

  • go

    github.com/sigstore/fulcio

  • go

    github.com/tektoncd/pipeline0.60.0

  • go

    github.com/tektoncd/pipeline1.1.0

  • go

    github.com/tektoncd/pipeline1.10.0

  • go

    github.com/tektoncd/pipeline1.4.0

  • go

    github.com/tektoncd/pipeline1.7.0

  • linuxfoundation

    tekton_pipelines1.1.0 – 1.3.3

  • linuxfoundation

    tekton_pipelines1.10.0 – 1.10.2

  • linuxfoundation

    tekton_pipelines1.4.0 – 1.6.1

  • linuxfoundation

    tekton_pipelines1.7.0 – 1.9.2

  • linuxfoundation

    tekton_pipelines

References & sources

Linked CVEs

IDCVE-2026-33211