StackRadar

CVE-2026-54167

High

Advisory

Published 20 Aug 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,781 indexed, latest versions
Container images
2
deployed by those charts
Fix available
1 of 1
affected package

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

Carried by container images the latest versions of 1 of 17,781 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
github.com/openshift-pipelines/pipelines-as-codegolangv0.15.00.37.82
OSV records
GHSA-f5f4-3hh4-f54m
Also known as
GO-2026-6266

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-54167.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
github.com/openshift-pipelines/pipelines-as-code@v0.15.0
0.37.8
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
github.com/openshift-pipelines/pipelines-as-code@v0.15.0
0.37.8

Open the chart page →

2,406

Container images carrying it

2 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
github.com/openshift-pipelines/pipelines-as-code@v0.15.0
0.37.8
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
github.com/openshift-pipelines/pipelines-as-code@v0.15.0
0.37.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.