Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
Go security advisories and CVEs.
Vulnerability disclosures, CVEs, security advisories, and patched releases.
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
Tekton Pipelines git resolver revision parameter argument injection in github.com/tektoncd/pipeline
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline
Path traversal in Tekton Pipelines git resolver in github.com/tektoncd/pipeline
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, i
When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it
The /debug/vars endpoint in Dgraph Alpha discloses the administrator's authentication token without requiring authentication. This allows an unauthenticated remote attacker to obtain the token and gai
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that coul
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that coul
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev
Gitea: Personal access token scope enforcement bypass on the repository home page ( ) discloses private repository contents in gitea.dev
Gitea Docker image: default lets any source IP impersonate any user via in code.gitea.io/gitea
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of 37698) in gitea.dev
