Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.2
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-27141 — golang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames CVE-2026-40938 — github.com/tektoncd/pipeline: Tekton Pipelines: Arbitrary code execution and secret exfiltration via malicious git commands
🎯 Affected products2
- Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:37f76414fb74a87e6aaa715e8a645fb9c4a5d383c9c232fc0a468760bafe0d63_amd64 as a component of Red Hat OpenShift Pipelines 1.21
✅ Remediation
Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:26538
- externalhttps://access.redhat.com/security/cve/CVE-2026-27141
- externalhttps://access.redhat.com/security/cve/CVE-2026-40938
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelines
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_26538.json