CVE-2026-33022 is a denial-of-service vulnerability affecting multiple versions of Tekton Pipelines, a Kubernetes-native CI/CD solution. An authenticated user with privileges to create TaskRuns or PipelineRuns can crash the controller cluster-wide by providing an overly long resolver name (31+ characters), leading to a panic during name generation and subsequent CrashLoopBackOff, effectively halting all CI/CD reconciliation. Rated Medium severity (CVSS 6.5), this vulnerability has a network attack vector and low attack complexity, requiring only low privileges to achieve a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability. Affected versions include 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1, with patches available in versions 1.0.1, 1.3.3, 1.6.1, 1.9.2 and 1.10.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.60.0, < 1.0.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.1.0, < 1.3.3CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.4.0, < 1.6.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.7.0, < 1.9.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.10.0, < 1.10.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.