{"api_version":"v1","generated_at":"2026-10-08T08:30:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-tektoncd-pipeline-bca5e8d95676","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/pipeline","name":"pipeline","next_cursor":null,"observations":[{"affected":">= 1.0.0, < 1.0.2; >= 1.2.0, < 1.3.4; >= 1.4.0, < 1.6.2; >= 1.7.0, < 1.9.3; >= 1.10.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2026-40923","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40923","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-22T15:41:51.388Z","patch_url":"","primary_source":"","published":"2026-04-21T20:50:53.742Z"},{"affected":">= 1.0.0, < 1.0.2; >= 1.2.0, < 1.3.4; >= 1.4.0, < 1.6.2; >= 1.7.0, < 1.9.3; >= 1.10.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2026-40924","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40924","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-22T16:03:53.528Z","patch_url":"","primary_source":"","published":"2026-04-21T20:47:47.178Z"},{"affected":"pipeline: >= 1.0.0, < 1.0.2, >= 1.2.0, < 1.3.4, >= 1.4.0, < 1.6.2, >= 1.7.0, < 1.9.3, >= 1.10.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2026-40938","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40938","fixed":"RHSA-2026:24359: Red Hat OpenShift Builds 1.7.3","last_modified":"2026-09-07T12:04:45.955Z","patch_url":"https://github.com/tektoncd/pipeline/security/advisories/GHSA-94jr-7pqp-xhcq","primary_source":"","published":"2026-04-21T20:45:24.658Z"},{"affected":">= 1.0.0, < 1.0.2; >= 1.2.0, < 1.3.4; >= 1.4.0, < 1.6.2; >= 1.7.0, < 1.9.3; >= 1.10.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2026-40161","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40161","fixed":"It is recommended that existing users of Red Hat OpenShift Builds 1.7.2 upgrade to 1.7.3","last_modified":"2026-05-21T21:20:13.227Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-40161","primary_source":"","published":"2026-04-21T16:26:27.381Z"},{"affected":">= 0.43.0, < 1.0.2; >= 1.2.0, < 1.3.4; >= 1.4.0, < 1.6.2; >= 1.7.0, < 1.9.3; >= 1.10.0, < 1.11.1","affected_versions_present":true,"cve_id":"CVE-2026-25542","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25542","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-22T16:06:24.202Z","patch_url":"https://github.com/tektoncd/pipeline/commit/b8905600322aa86327baae0a7c04d6cf1207362a","primary_source":"","published":"2026-04-21T16:05:43.217Z"},{"affected":"pipeline: >= 1.0.0, < 1.0.1, >= 1.1.0, < 1.3.3, >= 1.4.0, < 1.6.1, >= 1.7.0, < 1.9.2, >= 1.10.0, < 1.10.2","affected_versions_present":true,"cve_id":"CVE-2026-33211","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33211","fixed":"RHSA-2026:10155: Builds for Red Hat OpenShift 1.6.0","last_modified":"2026-09-07T12:05:00.228Z","patch_url":"https://github.com/tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5c","primary_source":"","published":"2026-03-23T23:55:54.089Z"},{"affected":">= 0.60.0, < 1.0.1; >= 1.1.0, < 1.3.3; >= 1.4.0, < 1.6.1; >= 1.7.0, < 1.9.2; >= 1.10.0, < 1.10.2","affected_versions_present":true,"cve_id":"CVE-2026-33022","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33022","fixed":"Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions.","last_modified":"2026-03-20T18:07:35.331Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-33022","primary_source":"","published":"2026-03-20T07:48:15.383Z"},{"affected":">= 0.35.0, <= 0.49.0","affected_versions_present":true,"cve_id":"CVE-2023-37264","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37264","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-11-04T20:23:21.819Z","patch_url":"","primary_source":"","published":"2023-07-07T16:23:09.866Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"tektoncd"}}
