THREAT OPS › Threat News › [NVD] CVE-2026-40938 (HIGH 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch withou
[NVD] CVE-2026-40938 (HIGH 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch withou
CVE-2026-40938 CVSS: 7.5 HIGH Published: 2026-04-21T21:16:46.283
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - chara
Indicators of compromise
- CVE-2026-40938cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40938