THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-40938 (HIGH 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch withou

[NVD] CVE-2026-40938 (HIGH 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch withou

lownvdPublished 2026-04-21

CVE-2026-40938 CVSS: 7.5 HIGH Published: 2026-04-21T21:16:46.283

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - chara

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40938