CVE-2026-25542Linuxfoundation · Tekton_pipelines
Vulnerability data via NVD (ingested)
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-25542product:"Linuxfoundation Tekton Pipelines"http.html:"Tekton Pipelines"More intel sources (5)
vuln:CVE-2026-25542vulnerabilities.cve_id: CVE-2026-25542CVE-2026-25542CVE-2026-25542"CVE-2026-25542" exploit -site:nvd.nist.gov