Description
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized token leakage via X‑GitHub‑Enterprise‑Host header manipulation
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the GitHub App provider component of Pipelines-as-Code. Prior to releases 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the application accepts the X‑GitHub‑Enterprise‑Host header as the API host while handling webhook events that include an installation.id. This check occurs before validating the webhook’s signature or verifying that the host in the signed payload matches the repository URL. An unauthenticated attacker who can reach the webhook endpoint can supply an arbitrary header value, causing the controller to issue a locally signed GitHub App JWT to the attacker‑controlled host. The short‑lived JWT can then be used to mint installation access tokens for the target repository during its validity window, limited only by the scopes granted to the GitHub App. The incoming webhook installation‑lookup path is also affected, but exploiting that path requires the valid incoming webhook secret for the target Repository CR. Consequently, an attacker could obtain privileged tokens that grant repository access and CI/CD capabilities.

Affected Systems

All releases of tektoncd:pipelines-as-code published before version 0.37.8, 0.39.6, 0.42.1, and 0.48.0 are affected. Users running any of those earlier versions, regardless of whether the GitHub App is installed, are within scope. The vulnerability is tied to the webhook endpoint of the application and does not depend on the presence of any specific configuration beyond the exposed header.

Risk and Exploitability

The CVSS score of 8.2 classifies this issue as high severity. The EPSS score is 0.00184, indicating a very low but nonzero probability of exploitation; however, the lack of authentication requirements and the potential to acquire installation tokens make the risk significant. The vulnerability is not listed in the CISA KEV catalog, indicating that no well‑known public exploits are documented. Likely attack vectors involve sending a crafted webhook payload that includes a forged X‑GitHub‑Enterprise‑Host header; if the JWT is captured, it may be used to mint tokens and gain repository or pipeline access.

Generated by OpenCVE AI on September 17, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pipelines-as-Code to version 0.37.8, 0.39.6, 0.42.1, 0.48.0, or any later release that validates the X‑GitHub‑Enterprise‑Host header before issuing a JWT
  • Configure the webhook endpoint to reject or whitelist the X‑GitHub‑Enterprise‑Host header, ensuring it matches the repository URL or a known trusted list of hosts
  • Require and verify a webhook signing secret before processing any request so that the header is checked only after signature validation

Generated by OpenCVE AI on September 17, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f5f4-3hh4-f54m Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tektoncd
Tektoncd pipelines-as-code
Vendors & Products Tektoncd
Tektoncd pipelines-as-code

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
Title Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Tektoncd Pipelines-as-code
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:49:57.706Z

Reserved: 2026-06-11T21:46:52.380Z

Link: CVE-2026-54167

cve-icon Vulnrichment

Updated: 2026-09-15T14:49:54.564Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:17.707

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-54167

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T14:29:45Z

Links: CVE-2026-54167 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:58:58Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity