OVERVIEW CVE-2026-40161 affects Tekton Pipelines, a Kubernetes-native continuous integration/continuous deployment (CI/CD) platform. The vulnerability exists in the git resolver component versions 1.0.0 through 1.10.0. When users omit the token parameter in API mode, the system inadvertently sends the configured Git API token (such as GitHub PATs or GitLab credentials) to a user-controlled server URL, creating an unintended credential exposure vector. SEVERITY The vulnerability carries a CVSS score of 7.7 (High) with a network-based attack vector requiring low complexity and low privilege requirements. The attack has cross-system scope, allowing a tenant with TaskRun or PipelineRun creation permissions to exfiltrate shared API tokens by redirecting the serverURL parameter to an attacker-controlled endpoint. The primary impact is confidentiality compromise of critical shared credentials, with no direct impact on integrity or availability. EXPLOITATION STATUS Currently, CVE-2026-40161 is not listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00029 indicates minimal probability of exploitation relative to other CVEs. Community attention remains low, suggesting limited public awareness or discourse regarding this vulnerability at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 1.10.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.