Summary
CVE-2026-54167 is an insufficient verification of data authenticity flaw (CWE-345) in Tekton Pipelines-as-Code’s GitHub App provider. Affected versions accept the X-GitHub-Enterprise-Host request header as the target API host when generating a GitHub App installation access token, and do so before the webhook signature is validated or the host is checked against the repository URL in the signed payload. This allows a remote, unauthenticated attacker to redirect the token-generation request to an attacker-controlled host and potentially capture the GitHub App JWT, rated High severity (CVSS 8.2).
Technical details
- Root cause: When a webhook payload contains an
installation.id, Pipelines-as-Code generates a GitHub App JWT and requests an installation access token using the API host supplied in theX-GitHub-Enterprise-Hostheader, without first validating the webhook signature or confirming that host matches the repository referenced in the signed payload. - Trigger conditions: The target Pipelines-as-Code deployment must use the GitHub App provider and expose its webhook endpoint to the attacker (directly or via a proxy that forwards custom headers).
- Attack vector: Network — an attacker sends a crafted webhook-style HTTP request containing an
installation.idand a maliciousX-GitHub-Enterprise-Hostvalue pointing to an attacker-controlled server, before signature validation occurs. - Impact: The attacker-controlled host can intercept the signed GitHub App JWT sent during token exchange, potentially enabling the attacker to mint unauthorized GitHub App installation access tokens, resulting in high confidentiality impact and limited integrity impact (no direct availability impact).
Affected software
- tektoncd/pipelines-as-code versions before 0.37.8
- versions 0.38.0 to before 0.39.6
- versions 0.40.0 to before 0.42.1
- versions 0.43.0 to before 0.48.0
(All versions up to and including 0.47.0 are vulnerable; the fix is first available in the listed patched releases.)
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Upgrade Pipelines-as-Code to v0.37.8, v0.39.6, v0.42.1, v0.48.0, or later, depending on the deployed release line. The fix validates the webhook signature before requesting a token, verifies the Enterprise host against the signed repository URL, and derives the host from the repository URL rather than the request header.
- If immediate patching is not possible:
- Strip or block the
X-GitHub-Enterprise-Hostheader at ingress/reverse-proxy layers in front of the Pipelines-as-Code webhook endpoint. - For deployments using GitHub.com (not GitHub Enterprise), reject any incoming webhook request that includes this header at all.
- Restrict network access to the Pipelines-as-Code webhook endpoint to trusted sources (e.g., GitHub’s published webhook IP ranges) where feasible.
- Rotate the associated GitHub App private key if compromise or exploitation is suspected.
- Strip or block the

