Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40161

26
FAUCET Score

OVERVIEW CVE-2026-40161 affects Tekton Pipelines, a Kubernetes-native continuous integration/continuous deployment (CI/CD) platform. The vulnerability exists in the git resolver component versions 1.0.0 through 1.10.0. When users omit the token parameter in API mode, the system inadvertently sends the configured Git API token (such as GitHub PATs or GitLab credentials) to a user-controlled server URL, creating an unintended credential exposure vector. SEVERITY The vulnerability carries a CVSS score of 7.7 (High) with a network-based attack vector requiring low complexity and low privilege requirements. The attack has cross-system scope, allowing a tenant with TaskRun or PipelineRun creation permissions to exfiltrate shared API tokens by redirecting the serverURL parameter to an attacker-controlled endpoint. The primary impact is confidentiality compromise of critical shared credentials, with no direct impact on integrity or availability. EXPLOITATION STATUS Currently, CVE-2026-40161 is not listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00029 indicates minimal probability of exploitation relative to other CVEs. Community attention remains low, suggesting limited public awareness or discourse regarding this vulnerability at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, <= 1.10.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 22nd percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.0.2
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.3.4
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.6.2
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.9.3
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.11.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-wjxp-xrpv-xpffhigh

Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL

Apr 21, 2026

References

github.com / tektoncd/pipeline/issues/9608
Issue Tracking
github.com / tektoncd/pipeline/issues/9609
Issue Tracking
github.com / tektoncd/pipeline/security/advisories/GHSA-wjxp-xrpv-xpff
Vendor Advisory