OVERVIEW CVE-2026-25542 affects Tekton Pipelines, a Kubernetes-based CI/CD orchestration platform, in versions 0.43.0 through 1.11.0. The vulnerability stems from improper validation of trusted resource verification policies, which use unanchored regular expressions to match resource source URIs against trusted patterns. Attackers can bypass these verification controls by crafting source strings that contain the trusted pattern as a substring, allowing them to circumvent intended security policies and apply unauthorized verification modes or cryptographic keys. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with a network attack vector, low complexity, and low privilege requirements. The primary impact is integrity compromise, enabling an authenticated attacker to manipulate which verification policies are applied to pipeline resources without requiring user interaction. While the attack does not directly affect confidentiality or availability, the ability to bypass cryptographic verification controls presents significant risk to CI/CD pipeline security and supply chain integrity. EXPLOITATION STATUS This vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.00029 indicates extremely low probability of exploitation. No public exploit code or proof-of-concept demonstrations are widely available, and community attention remains minimal, suggesting this remains a theoretical vulnerability requiring specific deployment configurations to exploit successfully.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.43.0, < 1.11.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.