RHSA-2026:6166HighCVSS 9.6
Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.1
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2026-33022 — github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:6166
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2026-33022
- externalhttps://access.redhat.com/security/cve/CVE-2026-33211
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelines
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6166.json