OVERVIEW CVE-2026-40924 affects Tekton Pipelines, a Kubernetes-native CI/CD platform, in versions prior to 1.11.1. The HTTP resolver's FetchHttpResource function fails to implement response body size limits when reading HTTP responses, allowing any tenant with permission to create TaskRuns or PipelineRuns to trigger a denial of service. The vulnerability exists in both the deprecated and current HTTP resolver implementations within the same pod that handles all resolver types. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM) with a network-based attack vector requiring low complexity and low privileges, resulting in high availability impact. An attacker can craft a malicious HTTP server returning an extremely large response body, causing the tekton-pipelines-resolvers pod to exhaust memory and be terminated by Kubernetes. Since all resolver types (Git, Hub, Bundle, Cluster, HTTP) operate within this single pod, exploitation denies resolution services cluster-wide and repeated attacks create sustained crash loops affecting CI/CD operations. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with an EPSS score of 0.0004 and the vulnerability currently absent from the Known Exploited Vulnerabilities (KEV) catalog. The vulnerability remains on inactive status in public tracking systems. However, exploitation requires only standard permissions within a multi-tenant cluster environment, making it accessible to lower-privileged users, and the fix is available in version 1.11.1 for immediate mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.