HIGH 8.2 GitHub
CVE-2026-54167
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
## Impact
Pipelines-as-Code installations using the GitHub App provider are vulnerable to GitHub App credential exfiltration through the webhook endpoint.
Affected versions accepted the `X-GitHub-Enterprise-Host` request header as the GitHub Enterprise API host during GitHub App token generation. For GitHub webhook events containing an `installation.id`, Pipelines-as-Code generated a GitHub App JWT and requested an installation access token before validating the webhook signature or checking t
Affected Products
- go/github.com/openshift-pipelines/pipelines-as-code >= 0.43.0, < 0.48.0
- go/github.com/openshift-pipelines/pipelines-as-code >= 0.40.0, < 0.42.1
- go/github.com/openshift-pipelines/pipelines-as-code >= 0.38.0, < 0.39.6
- go/github.com/openshift-pipelines/pipelines-as-code < 0.37.8
References
- https://github.com/advisories/GHSA-f5f4-3hh4-f54m
- https://github.com/tektoncd/pipelines-as-code/security/advisories/GHSA-f5f4-3hh4-f54m
- https://github.com/advisories/GHSA-f5f4-3hh4-f54m
This high severity vulnerability with a CVSS score of 8.2 was published on 2026-08-20 via GitHub. Affected: go/github.com/openshift-pipelines/pipelines-as-code >= 0.43.0, < 0.48.0, go/github.com/openshift-pipelines/pipelines-as-code >= 0.40.0, < 0.42.1, go/github.com/openshift-pipelines/pipelines-as-code >= 0.38.0, < 0.39.6 and 1 more.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.