Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54167— Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

Quick assessment

Affected
tektoncd pipelines-as-code
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Pipelines-as-Code 是一个 CI/CD 系统,允许用户在源代码仓库中定义 Tekton 流水线。在 0.37.8、0.39.6、0.42.1 和 0.48.0 版本之前,GitHub App 提供程序在处理包含 installation.id 的 webhook 事件时,会在验证 webhook 签名或确认主机与签名负载中仓库 URL 匹配之前,就接受 X-GitHub-Enterprise-Host 作为 API 主机。能够访问 webhook 端点的未认证攻击者可以选择一个由攻击者控制的主机,并

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 4

VendorProduct Version RangeStatus
tektoncd pipelines-as-code < 0.37.8 affected
>= 0.38.0, < 0.39.6 affected
>= 0.40.0, < 0.42.1 affected
>= 0.43.0, < 0.48.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54167

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
Source: CVE Program / CVE List V5
Vulnerability Description
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tektoncd pipelines-as-code < 0.37.8 -

II. Public POCs for CVE-2026-54167

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54167

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54167 (1)

Vendor Advisories for CVE-2026-54167 (1)

Vendor Pages for CVE-2026-54167 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54167

No comments yet


Leave a comment