RHSA-2026:10066HighCVSS 9.6

Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.4

Published
April 23, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-33022 — github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver

🎯 Affected products2

  • Red Hat OpenShift Pipelines 1.2
  • registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:8cadde0c138f382b9da827165ddcc141e81f864d389dcb17d270e420c33d1085_amd64 as a component of Red Hat OpenShift Pipelines 1.2

✅ Remediation

Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, restrict the creation of ResolutionRequests to trusted users and service accounts. Implement strict Role-Based Access Control (RBAC) policies to limit which tenants can create TaskRuns or PipelineRuns that utilize the Tekton Pipelines git resolver. This reduces the exposure by preventing unauthorized access to the resolver pod's filesystem.

🔗 References (6)