Denial of Service Vulnerability in Tekton Pipelines by Tekton Project
CVE-2026-40924

6.5MEDIUM

Key Information:

Vendor

Tektoncd

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40924?

The Tekton Pipelines project, designed to provide Kubernetes-style resources for CI/CD workflows, contains a vulnerability in its HTTP resolver component. Prior to version 1.11.1, the FetchHttpResource function is susceptible to denial of service due to unrestricted response body sizes. This allows an attacker, with permission to create TaskRuns or PipelineRuns, to direct the resolver to an external HTTP server that returns excessively large responses, potentially causing the associated tekton-pipelines-resolvers pod to be out-of-memory (OOM) killed by Kubernetes. This issue affects all resolver types, including Git, Hub, Bundle, Cluster, and HTTP, as they operate within the same pod. Continuous exploitation can lead to persistent crash loops, impacting the entire resolution service across the cluster. The vulnerability is addressed in the latest version 1.11.1.

Affected Version(s)

pipeline < 1.11.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.