CVE Explorer
CVE-2026-40924
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HTTP resolver can point it at an attacker-controlled HTTP server that returns a very large response body within the 1-minute timeou
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pipeline","vendor":"tektoncd","versions":[{"status":"affected","version":">= 1.0.0, < 1.0.2"},{"status":"affected","version":">= 1.2.0, < 1.3.4"},{"status":"affected","version":">= 1.4.0, < 1.6.2"},{"status":"affected","version":">= 1.7.0, < 1.9.3"},{"status":"affected","version":">= 1.10.0, < 1.11.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/tektoncd/pipeline/releases/tag/v1.11.1","tags":["x_refsource_MISC"],"url":"https://github.com/tektoncd/pipeline/releases/tag/v1.11.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/adp/0/references/0
{"name":"https://github.com/tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74","tags":["x_refsource_CONFIRM"],"url":"https://github.com/tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e5594da30fa68aa1f448ef4c93d7d20bfa8604f8be111a57083d997220f185c · sha256:cc014254041cfbc6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.