Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.21.1
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2026-33022 — github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver
🎯 Affected products145
- Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:2447d379a4ff5ac40fd31a4f598815d195fa6922dcddc8646fb7b0ab1fa2f2c3_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:37e8aa491d789e8d1fc8f3a3af517093c237691ca2ad96b4bc3fdb816aa88df4_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:6799cba68b1738f0a7978335634d87f4a7443a70312be654e6997f96e918952b_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cache-rhel9@sha256:fe6e5cd6c9dca5cb5cf20e26f9406abb4bf4dca5a50146e32bc98090ce4a2a67_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:003246997588f6030f5488d6a0ae50daaf4970a1bb39092d4c762b407ba63d3e_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:968593d98e638637f271c74d5b13cd227b8587e013e8d71bc8c7faf25cf031ac_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:ca3a9b04d388b008542e3d6c3ba2bb93f4ec7056fd9e5a7a7a26714d10d293bd_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-chains-controller-rhel9@sha256:e589e8566f17e1bf4eed74f3ccd61b2e77d5cab7cb2bb091b76e758e5682a948_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:30c78cb17c2dbb124077332e5aba2626fc34833f17d9ffc43265ead4512b1215_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:7e0b8f06a88f2b7488c2fac5ebaaec362080c613294526998d948f580505d265_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:f49b06a428800b6ebdf0393694ed0d3e1c698b2844d0948769b6aeef6d5b23ab_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:fa64c0d948ac9564dea11cbd94186f00a08c0dac162f5ec7441f9d859d0646bd_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:4e2e9e5bf18f63e584ec8506d96dcc6d0ad1fbdab3c2a5682a46c58ae969cde6_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:77af18020d2d8733ed028dec7fd78c5e9f2dfa2272f352ee45de8f711d93c52e_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:8ef288bcc668b0dc2f0c9305abe0546f07cf7535cb083495210aa3219ab72dc1_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:f99f5612487516a28ca3e63682afa1350fa60307a97f50c086cc1467d155ca58_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:3fcac1d8ade2f968d743f6bcc1d505933746e6dd83878ff2f1656cec005a107c_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:48cddef1afef357f64e11065ce93392063d5d9c2795cf3b8aaf92d21f54959f4_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:511965e5eb2f3c857864644803d49dceb639ad8190132f21dfd82bae2544b114_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:f77cef165f2e2b770833ee3532a473d5a1731502aa5936835c25511a2c37d7c1_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:2d2d1b8900245ac1cc3b8ff363e65aac0c44155961508f4e0b17d7c9ebcfdf9d_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:780171539b9e364a5bcee51b4843aebd950d499c75bc579bb78cbc1265a2ff23_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:d9a5e8233a92c81a77adeae8b4b742f8bc234457c0d017131df86c6aa867438c_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-entrypoint-rhel9@sha256:f6553c2db04c86384e30e9bfaea8d4270f19bab9afd7869d27032fe38534b295_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:20db9235bcb1e1e11b6815cd1ab889a6a162713344b9538f679660ad1d8e4b81_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:7c35e644ad8d4643bcd661d619894b86eb7461d42295806e91cff5c18fe4551d_amd64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:875b5369e4d5d2ed1e55d39eb0d7a42694324643f0b4bbcfb2be762a0e17719f_arm64 as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-events-rhel9@sha256:94fd1a0b0764991eda81a160f9e4c4087883520c22bb17f9bd9d3167892861cf_s390x as a component of Red Hat OpenShift Pipelines 1.21
- registry.redhat.io/openshift-pipelines/pipelines-git-init-rhel9@sha256:0ccf22fd76c5fe03b06340a925735ff6612b528cd6c4ab642f59d6033d8172d9_ppc64le as a component of Red Hat OpenShift Pipelines 1.21
- +115 more not shown
✅ Remediation
Red Hat OpenShift Pipelines is a cloud-native, continuous integration and continuous delivery (CI/CD) solution based on Kubernetes resources. It uses Tekton building blocks to automate deployments across multiple platforms by abstracting away the underlying implementation details. Tekton introduces a number of standard custom resource definitions (CRDs) for defining CI/CD pipelines that are portable across Kubernetes distributions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, restrict the creation of ResolutionRequests to trusted users and service accounts. Implement strict Role-Based Access Control (RBAC) policies to limit which tenants can create TaskRuns or PipelineRuns that utilize the Tekton Pipelines git resolver. This reduces the exposure by preventing unauthorized access to the resolver pod's filesystem.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:6166
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2026-33022
- externalhttps://access.redhat.com/security/cve/CVE-2026-33211
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelines
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6166.json