16 Total advisories
16 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/tektoncd/pipeline is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.7
CVE-2026-40161
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
MEDIUM 6.5
CVE-2026-25542
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
MEDIUM 5.4
CVE-2026-40923
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
HIGH 7.5
CVE-2026-40938
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
MEDIUM 6.5
CVE-2026-40924
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
CRITICAL 9.6
CVE-2026-33211
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
MEDIUM 6.5
CVE-2026-33022
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
LOW 3.7
CVE-2023-37264
Pipelines do not validate child UIDs
UNKNOWN
CVE-2026-40923
Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-40938
Tekton Pipelines git resolver revision parameter argument injection in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-33211
Path traversal in Tekton Pipelines git resolver in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-33022
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-40161
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-25542
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
UNKNOWN
CVE-2026-40924
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
UNKNOWN
CVE-2023-37264
Pipelines do not validate child UIDs in github.com/tektoncd/pipeline
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes