Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40924

24
FAUCET Score

OVERVIEW CVE-2026-40924 affects Tekton Pipelines, a Kubernetes-native CI/CD platform, in versions prior to 1.11.1. The HTTP resolver's FetchHttpResource function fails to implement response body size limits when reading HTTP responses, allowing any tenant with permission to create TaskRuns or PipelineRuns to trigger a denial of service. The vulnerability exists in both the deprecated and current HTTP resolver implementations within the same pod that handles all resolver types. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM) with a network-based attack vector requiring low complexity and low privileges, resulting in high availability impact. An attacker can craft a malicious HTTP server returning an extremely large response body, causing the tekton-pipelines-resolvers pod to exhaust memory and be terminated by Kubernetes. Since all resolver types (Git, Hub, Bundle, Cluster, HTTP) operate within this single pod, exploitation denies resolution services cluster-wide and repeated attacks create sustained crash loops affecting CI/CD operations. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with an EPSS score of 0.0004 and the vulnerability currently absent from the Known Exploited Vulnerabilities (KEV) catalog. The vulnerability remains on inactive status in public tracking systems. However, exploitation requires only standard permissions within a multi-tenant cluster environment, making it accessible to lower-privileged users, and the fix is available in version 1.11.1 for immediate mitigation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.11.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 32nd percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.11.1
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.0.2
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.3.4
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.6.2
gopatch availablevia ghsa
Product: github.com/tektoncd/pipelineFixed in: 1.9.3
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-m2cx-gpqf-qf74medium

Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion

Apr 21, 2026

References

github.com / tektoncd/pipeline/releases/tag/v1.11.1
Release Notes
github.com / tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74
ExploitVendor Advisory