VerificationPolicy regex pattern bypass via substring matching
Upstream fixed versions: github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
details
- Finding IDs
- F-TEKTON-REGEX-001
- CVE
- CVE-2026-25542
- GHSA
- GHSA-rmx9-2pp3-xhcr
- Status
- patched
- Fixed in
- github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
- Recorded credit
- reporter: @1seal
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- VerificationPolicy regex pattern bypass via substring matching
- Upstream CWE
- CWE-185
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
- Upstream affected ranges
- github.com/tektoncd/pipeline: >= 0.43.0, <= 1.7.0 (also present on main at 0133513db03dadb3cb08801d6b0330badcb63830)
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-TEKTON-REGEX-001: Verification failures. A partial regular-expression match weakens the verification policy. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TEKTON-REGEX-001
Security area (1seal assessment): Authorization. A partial regular-expression match weakens the verification policy. Reviewed 24 Sep 2026.