RHSA-2026:6170HighCVSS 9.6

Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.1

Published
March 30, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (4)

CVE-2026-33022 · pendingCVE-2026-33211 · pendingCVE-2025-66506CVE-2026-25639

📋 Description

CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-33022 — github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver

🔗 References (8)