Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.5
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-1526 — undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression CVE-2026-1528 — undici: undici: Denial of Service via crafted WebSocket frame with large length CVE-2026-2229 — undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
🎯 Affected products141
- Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:3c7e750a8230733a4f482aee3c4c000a67e52c8f5f149273e609b98fd18ddb10_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:5d2a1ee4f9a0fbb0a9d56d7b6c1fd94241cdc02a9d192ee8f4e004f9f0dd0cd8_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:e9561cd2ffa12f446af4b3618bf99575084e7c0e2c8972c0a112dd1580fb0515_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:f470f482deeebe42ebc4fbc2c5c8ddae8c0c9e71ebb45abf150e1221b18e8621_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:37a363f8aab7c6bc87729d98ff32a44669e033ef1598cd6275262b3aec7a7950_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:a7a9fad55880a24ef13252871a7eac22efef85d4f50ea71979d97f7dba504fa7_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:addbf352dd4cbb2b7fdf16ac57d2ff8d4a6f72701b3ac75a1194debbfbfc0e96_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:cfbf1f68e6896abb7f2795c49e51d2d607534555ba4b754eb79c90ff40955f99_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:5066441d93db8c875c341307083d71371fbf656d22036d1cdc6d07c5f4363e15_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:ac0f4351612091aceeb5de41e0776ad9fffce43c15cea5cf82e23655f9e83491_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:eb396c01ff2ff283850eff1469eda34bc964cc512bc33b031b62c89ebee45643_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:feaa053f49eb5d7f890647a0b6f365a80b82b18988a0f6d5467221bc52a6cb7e_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:629e0d9b1ca93751ad9f19328ef65019179fa886d9029088380a429532dc6681_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:aa1af86676fae99c0e2f3ea50ca2ba44223ccb4289c884d65cfacdd286e85d31_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:f1ba93478d47803d30cf65bea363e7d6e660683e4a2245979f009117b6f6fe5c_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:0edb8944b49cd12ee073cdcd26ce61e0ff95fac17b3133e1c4b939962f4b54ae_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:d7f65bf6390c8d16e4db818d1d4133d289cda151a9d6c1196b106416971a9061_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:d82e2c22fc88b0069dfc535797a7fe50113ebbfc0b3492c952eff0ccd0496029_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:f5f7b0cd1a79d803b6027c264a041cde6fe8e6b9b26279ebc901e8ef4afa20f0_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:03f625e0c0c406ce688b18485b8b310f7de4fec4e6fcd7eec6b31d8f0e5613e2_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:39656fa56396d5c31e25331d03948b3ad5067cc4119f24d9c0ad0f2185a8b9a0_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:4a4d0bf0eae7b1d07cf7a37a0bcbf862f9eacc0ff6a6aaaf935cbd20e90e67ed_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:ce50f39a31b70bad477cfe217341ac62328fc63d5380dd34547a494ce9f896bb_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:2108be73f60cb77d8e639d694429efee711e358f3b0d6a46068b0be1ce13a478_ppc64le as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:401db4e85fffd7670f702658dd1c02c07640f07667f66984a0b52ebd491062f9_s390x as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:f09ace1d218c3e544591176706376fe7c30a0a83b332b4b11f6c0de5c0fdb622_arm64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:fa4480d53c94a4865fe6924588cb17f52be93948abb76b5dac2356bf95d49af3_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- registry.redhat.io/openshift-pipelines/pipelines-hub-api-rhel9@sha256:3347495c87dcfaf7cdd83a156d7e1cd6a09b396ef028999aa28fcd5a48e10b0e_amd64 as a component of Red Hat OpenShift Pipelines 1.2
- +111 more not shown
✅ Remediation
Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, restrict the creation of ResolutionRequests to trusted users and service accounts. Implement strict Role-Based Access Control (RBAC) policies to limit which tenants can create TaskRuns or PipelineRuns that utilize the Tekton Pipelines git resolver. This reduces the exposure by preventing unauthorized access to the resolver pod's filesystem.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:21931
- externalhttps://access.redhat.com/security/cve/CVE-2026-1526
- externalhttps://access.redhat.com/security/cve/CVE-2026-1528
- externalhttps://access.redhat.com/security/cve/CVE-2026-2229
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33211
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelines
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_21931.json