5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.jenkins.plugins:pipeline-groovy-lib is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.3
CVE-2026-57284
Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types
MEDIUM 4.3
CVE-2026-57283
Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
HIGH 7.5
CVE-2026-48921
Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
HIGH 8.8
CVE-2022-43406
Sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin
HIGH 8.8
CVE-2022-43405
Sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin and Pipeline: Deprecated Groovy Libraries Plugin
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes