Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33211

37
FAUCET Score

CVE-2026-33211 is a critical path traversal vulnerability found in Tekton Pipelines versions 1.0.0 up to 1.10.2 (excluding patched releases). This flaw allows an authenticated tenant to read arbitrary files, such as ServiceAccount tokens, from the resolver pod's filesystem via the pathInRepo parameter. With a CVSS score of 9.6 CRITICAL, it presents a network attack vector requiring low privileges and complexity, leading to high confidentiality and integrity impacts. There is no evidence of active exploitation or public exploit code, though it has received limited community discussion. Remediation involves upgrading to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.0, < 1.3.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*
>= 1.4.0, < 1.6.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*
>= 1.7.0, < 1.9.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*
>= 1.10.0, < 1.10.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:1.0.0:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 46th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.0.1
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.3.3
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.6.1
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.9.2
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.10.2

Vendor Advisories (1)

goGHSA-j5q5-j9gm-2w5ccritical

Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod

Mar 18, 2026

References

access.redhat.com / errata/RHSA-2026:10026
access.redhat.com / errata/RHSA-2026:10066
access.redhat.com / errata/RHSA-2026:10125
access.redhat.com / errata/RHSA-2026:10155
access.redhat.com / errata/RHSA-2026:10158
access.redhat.com / errata/RHSA-2026:21931
access.redhat.com / errata/RHSA-2026:21932
access.redhat.com / errata/RHSA-2026:24484
access.redhat.com / errata/RHSA-2026:6166
access.redhat.com / errata/RHSA-2026:6170
access.redhat.com / security/cve/CVE-2026-33211
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33211.json
github.com / tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c
Patch
github.com / tektoncd/pipeline/commit/318006c4e3a5
Patch
github.com / tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd
Patch
github.com / tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae
Patch
github.com / tektoncd/pipeline/commit/b1fee65b88aa969069c14c120045e97c37d9ee5e
Patch
github.com / tektoncd/pipeline/commit/cdb4e1e97a4f3170f9bc2cbfff83a6c8107bc3db
Patch
github.com / tektoncd/pipeline/commit/ec7755031a183b345cf9e64bea0e0505c1b9cb78
Patch
github.com / tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5c
PatchVendor Advisory