Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/tektoncd/pipeline
  4. ›
  5. CVE-2026-40161

CVE-2026-40161: Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL

April 21, 2026 (updated May 21, 2026)

The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint.

References

  • github.com/advisories/GHSA-wjxp-xrpv-xpff
  • github.com/tektoncd/pipeline/issues/9608
  • github.com/tektoncd/pipeline/issues/9609
  • github.com/tektoncd/pipeline/security/advisories/GHSA-wjxp-xrpv-xpff
  • nvd.nist.gov/vuln/detail/CVE-2026-40161

Code Behaviors & Features

Detect and mitigate CVE-2026-40161 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.0.0 before 1.0.2, all versions starting from 1.2.0 before 1.3.4, all versions starting from 1.4.0 before 1.6.2, all versions starting from 1.7.0 before 1.9.3, all versions starting from 1.10.0 before 1.11.1

Fixed versions

  • 1.0.2
  • 1.3.4
  • 1.6.2
  • 1.9.3
  • 1.11.1

Solution

Upgrade to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1 or above.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-201: Insertion of Sensitive Information Into Sent Data

Source file

go/github.com/tektoncd/pipeline/CVE-2026-40161.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:42 +0000.