Skip to main content

CVE-2026-54167: CWE-345: Insufficient Verification of Data Authenticity in tektoncd pipelines-as-code

0
High
VulnerabilityCVE-2026-54167cvecve-2026-54167cwe-345
Published: 09/15/2026 (09/15/2026, 14:29:45 UTC)
Source: CVE Database V5
Vendor/Project: tektoncd
Product: pipelines-as-code

Description

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected software

tektoncd

pipelines-as-code

Affected versions
<0.37.8>=0.38.0 <0.39.6>=0.40.0 <0.42.1>=0.43.0 <0.48.0
GitHub Actionsmore threats →ai
tektoncd/pipelines-as-code
pkg:github/tektoncd/pipelines-as-code
Affected versions
<0.37.8>=0.38.0 <0.39.6>=0.40.0 <0.42.1>=0.43.0 <0.48.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 15:16:33 UTC

Technical Analysis

Tekton Pipelines-as-Code prior to versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0 contains an insufficient verification of data authenticity vulnerability (CWE-345) in its GitHub App webhook processing. Specifically, the GitHub App provider accepts the X-GitHub-Enterprise-Host header as the API host before validating the webhook signature or confirming that the host matches the repository URL in the signed payload. This flaw allows an unauthenticated attacker who can reach the webhook endpoint to specify an attacker-controlled host, causing the controller to send a locally signed GitHub App JWT to that host. The exposed JWT may be used to attempt minting installation access tokens within the JWT's validity window, subject to the GitHub App's installation and permissions. The installation-lookup path is also affected but requires a valid webhook secret for exploitation. The vulnerability is addressed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.

Potential Impact

An unauthenticated attacker able to reach the webhook endpoint can cause the system to send a signed GitHub App JWT to an attacker-controlled host. This JWT could be used to attempt minting installation access tokens, potentially allowing unauthorized access to GitHub App resources within the scope of the app's permissions. The impact includes potential unauthorized access to CI/CD pipeline operations or repository data. However, exploitation of the installation-lookup path requires a valid webhook secret, limiting attack vectors. There are no known exploits in the wild at this time.

Mitigation Recommendations

This vulnerability is fixed in Tekton Pipelines-as-Code versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0. Users should upgrade to one of these versions or later to remediate the issue. No other mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-11T21:46:52.380Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa95dfa55bf5e2cf5f98f54

Added to database: 09/15/2026, 15:02:18 UTC

Last enriched: 09/15/2026, 15:16:33 UTC

Last updated: 09/15/2026, 22:11:32 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses