<Vulnerability name="CVE-2026-54167">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-15T14:29:45</PublicDate>
    <Bugzilla id="2533858" url="https://bugzilla.redhat.com/show_bug.cgi?id=2533858" xml:lang="en:us">
github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: GitHub App token redirection via untrusted host header
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.2</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-345</CWE>
    <Details xml:lang="en:us" source="Mitre">
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload. An unauthenticated attacker who can reach the webhook endpoint can select an attacker-controlled host and cause the controller to send a locally signed GitHub App JWT to that service. The exposed JWT may be used to attempt to mint installation access tokens during its validity window, subject to the GitHub App installation and permissions. The incoming webhook installation-lookup path is also affected, but exploitation of that path requires the valid incoming webhook secret for the target Repository CR. This issue is fixed in versions 0.37.8, 0.39.6, 0.42.1, and 0.48.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Pipelines-as-Code. The GitHub App provider incorrectly processes webhook events by accepting an untrusted X-GitHub-Enterprise-Host header as the API host before validating the webhook signature. An unauthenticated attacker can exploit this by sending a specially crafted webhook request, causing the system to send a locally signed GitHub App JSON Web Token (JWT) to an attacker-controlled service. This exposed JWT could then be used to attempt to generate installation access tokens, potentially leading to unauthorized access or actions within the GitHub App installation.
    </Details>
    <Statement xml:lang="en:us">
This flaw has an Important impact because vulnerable Pipelines-as-Code GitHub App webhook deployments can disclose a locally signed GitHub App JWT to an attacker-controlled host. An unauthenticated remote attacker who can reach the webhook endpoint can supply an untrusted Enterprise-host header; the exposed JWT may enable installation-token minting within its validity window and configured permissions.
    </Statement>
    <Mitigation xml:lang="en:us">
Until a patched release is deployed, block or strip unexpected X-GitHub-Enterprise-Host headers at the ingress or proxy in front of the Pipelines-as-Code webhook endpoint. For GitHub.com installations, reject requests containing this header; for GitHub Enterprise Server, permit only the expected hostname. Restrict webhook access to trusted Git provider sources where possible, and rotate the GitHub App private key if compromise is suspected.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:openshift_builds:1">
        <ProductName>Builds for Red Hat OpenShift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-builds/openshift-builds-rhel10-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_builds:1">
        <ProductName>Builds for Red Hat OpenShift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-builds/openshift-builds-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines-client</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-cli-tkn-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-cli-tkn-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-opc-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-pipelines/pipelines-operator-proxy-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-pipelines/pipelines-operator-proxy-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-operator-webhook-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-operator-webhook-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-pipelines/pipelines-rhel8-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_pipelines:1">
        <ProductName>OpenShift Pipelines</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-pipelines/pipelines-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-serverless-1/kn-client-kn-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-serverless-1/kn-plugin-func-func-util-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift-serverless-clients</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_devspaces:3">
        <ProductName>Red Hat OpenShift Dev Spaces</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>devspaces/udi-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:webterminal:1">
        <ProductName>Red Hat Web Terminal</ProductName>
        <FixState>Affected</FixState>
        <PackageName>web-terminal/web-terminal-tooling-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-54167
https://nvd.nist.gov/vuln/detail/CVE-2026-54167
https://github.com/tektoncd/pipelines-as-code/commit/402d5c7eeece881cb082ec68e9e8b61709e39ace
https://github.com/tektoncd/pipelines-as-code/commit/40813976a77920feaf52671320d6d3c5ff08eb7e
https://github.com/tektoncd/pipelines-as-code/commit/ac6fded6dfb69ade7197d4eeed6e90ddbe1b79bc
https://github.com/tektoncd/pipelines-as-code/commit/e0c4a11ea3800ab9d26cf3a8ae92b74cf18527c3
https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.37.8
https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.39.6
https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.42.1
https://github.com/tektoncd/pipelines-as-code/releases/tag/v0.48.0
https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m
    </References>
</Vulnerability>