Known Vulnerabilities for Pipelines-as-code by Tektoncd
Listed below are 10 of the newest known vulnerabilities associated with "Pipelines-as-code" by "Tektoncd".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92129 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-92126 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy m... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-92125 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-92124 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements ... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-92123 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-92122 json | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created w... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-75926 json | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel,... | Not Provided | 2026-08-18 | 2026-09-24 |
| CVE-2026-55588 json | ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and ... | Not Provided | 2026-08-25 | 2026-08-27 |
| CVE-2026-54168 json | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.3... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-54167 json | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.3... | Not Provided | 2026-09-15 | 2026-09-15 |