CVE-2026-33211
Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.1
Description
A flaw was found in Tekton Pipelines, specifically in the Tekton Pipelines git resolver. A tenant with permissions to create ResolutionRequests can exploit a path traversal vulnerability via the `pathInRepo` parameter. This allows the tenant to read arbitrary files from the resolver pod's filesystem, leading to information disclosure, including sensitive ServiceAccount tokens. The contents of these files are returned in a base64-encoded format.
Metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-07 13:18 UTC· security-advisories@github.com
- Reference: https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c
- Reference: https://github.com/tektoncd/pipeline/commit/318006c4e3a5
- Reference: https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd
- Reference: https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae
- CVE Modified2026-09-07 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33211.json">CVE-2026-33211</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:10026
- Reference: https://access.redhat.com/errata/RHSA-2026:10066
- Reference: https://access.redhat.com/errata/RHSA-2026:10125
- CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48) → Red Hat OpenShift Builds 1.6.4, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Pipelines 1.2 (+48)
- CVE Modified2026-08-03 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48) → Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.3, Red Hat OpenShift Pipelines 1.2 (+48)
- CVE Modified2026-07-27 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.1, Red Hat OpenShift Pipelines 1.2 (+48) → Builds for Red Hat OpenShift 1.6.0, Red Hat OpenShift Builds 1.7.4, Red Hat OpenShift Pipelines 1.2 (+48)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
axios
axios1.0.0 – 1.13.5
axios
axios0.30.3
go
github.com/sigstore/fulcio
go
github.com/tektoncd/pipeline0.60.0
go
github.com/tektoncd/pipeline1.1.0
go
github.com/tektoncd/pipeline1.10.0
go
github.com/tektoncd/pipeline1.4.0
go
github.com/tektoncd/pipeline1.7.0
linuxfoundation
tekton_pipelines1.1.0 – 1.3.3
linuxfoundation
tekton_pipelines1.10.0 – 1.10.2
linuxfoundation
tekton_pipelines1.4.0 – 1.6.1
linuxfoundation
tekton_pipelines1.7.0 – 1.9.2
linuxfoundation
tekton_pipelines
References & sources
- https://github.com/tektoncd/pipeline/security/advisories/GHSA-cv4x-93xx-wgfjadvisory
- https://github.com/tektoncd/pipeline/commit/5eead3f859b9fix
- https://github.com/tektoncd/pipeline/commit/01673237c464fix
- https://github.com/tektoncd/pipeline/commit/edc64bbf2232fix
- https://github.com/tektoncd/pipeline/commit/0fa2d66cff81fix
- https://github.com/tektoncd/pipeline/commit/5e4905fb6754fix
- https://github.com/tektoncd/pipeline/commit/ebc197e2b973fix
- https://github.com/tektoncd/pipeline/commit/5eead3f859b9f938e86039e4d29185092c1d4ee6x_refsource_MISC
- https://github.com/tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5cadvisory
- https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687cx_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/318006c4e3a5x_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbdx_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75aex_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/b1fee65b88aa969069c14c120045e97c37d9ee5ex_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/cdb4e1e97a4f3170f9bc2cbfff83a6c8107bc3dbx_refsource_MISC
- https://github.com/tektoncd/pipeline/commit/ec7755031a183b345cf9e64bea0e0505c1b9cb78x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2026-33211vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2450554issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33211.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:10155vendor-advisoryx_refsource_REDHAT