
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33022 is a denial-of-service vulnerability in the Tekton Pipelines controller that allows any low-privileged user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by specifying a resolver name of 31 or more characters. It affects versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 of the Linux Foundation's github.com/tektoncd/pipeline Go module. The vulnerability was reported by Oleh Konko (@1seal), published on March 16, 2026, and assigned a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Red Hat Bugzilla).
The root cause is an improper validation of an array index (CWE-129) in the GenerateDeterministicNameFromSpec function, which constructs a deterministic ResolutionRequest name in the format {resolver}-{hash}. When the resolver name is 31 or more characters, the combined string exceeds the DNS-1123 label limit of 63 characters, triggering a truncation code path that calls strings.LastIndex(name[:maxLength], " "). Because the generated name never contains spaces, LastIndex returns -1, which is then used as a slice bound (name[:-1]), causing a Go runtime panic (Github Advisory). The vulnerable truncation logic was introduced in commit ea1fa7ad1fdc ("Remote Resolution Refactor"), first released in v0.60.0 on 2024-05-22. Built-in resolvers (git, cluster, bundles, hub) have short names and are not affected under normal usage; only custom resolver names of sufficient length trigger the bug (Github Advisory).
Successful exploitation causes the Tekton Pipelines controller to panic and enter a CrashLoopBackOff restart loop, because the offending TaskRun or PipelineRun is re-reconciled on each restart. This blocks all CI/CD reconciliation cluster-wide — affecting every TaskRun and PipelineRun in the cluster — until the malicious resource is manually deleted by an administrator. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue, but its cluster-wide scope makes it highly disruptive to any organization relying on Tekton for CI/CD automation (Github Advisory, Red Hat Bugzilla).
A proof-of-concept was provided by the reporter (Oleh Konko, @1seal) as part of the responsible disclosure, though no public exploit code has been released. The EPSS score is approximately 0.021% (6th percentile), indicating a low probability of active exploitation in the near term (Github Advisory). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low privileges (the ability to create TaskRun or PipelineRun resources), making it accessible to any authenticated cluster user with standard developer permissions.
create or update permissions on TaskRun or PipelineRun resources in any namespace on a vulnerable Tekton Pipelines installation (v0.60.0–v1.10.1).TaskRun or PipelineRun YAML manifest with .spec.taskRef.resolver (or .spec.pipelineRef.resolver) set to a custom resolver name of 31 or more characters, for example:apiVersion: tekton.dev/v1
kind: TaskRun
metadata:
name: dos-taskrun
spec:
taskRef:
resolver: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa # 33 characterskubectl apply -f dos-taskrun.yaml.GenerateDeterministicNameFromSpec, generates a name exceeding 63 characters, and panics on the name[:-1] slice bound.CrashLoopBackOff. All CI/CD reconciliation cluster-wide is blocked until an administrator manually deletes the offending resource (Github Advisory).panic: runtime error: slice bounds out of range [:-1] originating from GenerateDeterministicNameFromSpec; repeated controller crash and restart events in Kubernetes event logs.CrashLoopBackOff status on the tekton-pipelines-controller pod in the tekton-pipelines namespace; kubectl get pods -n tekton-pipelines showing repeated restarts.TaskRun or PipelineRun resource with .spec.taskRef.resolver or .spec.pipelineRef.resolver set to a string of 31 or more characters, particularly one created by an unexpected or unauthorized user.TaskRun and PipelineRun resources stuck in a pending/unreconciled state cluster-wide (Github Advisory).Upgrade to one of the patched versions: 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2, depending on the release branch in use. The fix correctly truncates only the resolver-name prefix (rather than the full generated string) before appending the hash, ensuring the result stays within the DNS-1123 63-character limit and eliminating the -1 slice bound panic (Github Advisory). As a workaround where patching is not immediately possible, restrict create and update permissions on TaskRun and PipelineRun resources to trusted users only via Kubernetes RBAC; the advisory notes there is no validation-side workaround without patching. If the controller is already in CrashLoopBackOff, manually delete the offending TaskRun or PipelineRun resource to restore normal operation.
Red Hat tracked the vulnerability via their security response process (Bugzilla bug 2449483) and assigned it medium severity, with their Product Security DevOps Team listed as the assignee (Red Hat Bugzilla). SUSE issued a security announcement referencing the vulnerability, and it was covered in Linux security advisory aggregators (openSUSE Security). The Tekton maintainers acknowledged the reporter (Oleh Konko, @1seal) for providing a thorough analysis, proof-of-concept, and fix review (Github Advisory). Community reaction has been limited, consistent with the moderate severity rating and absence of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."