VDB
KO

GO-2026-5486

Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion in github.com/tektoncd/pipeline

Details

Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion in github.com/tektoncd/pipeline

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/tektoncd/pipeline
Introduced in: 1.0.0 Fixed in: 1.0.2
Fix go get github.com/tektoncd/pipeline@v1.0.2

References