Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Jenkins has a Denial of service vulnerability in HTTP-based CLI

GHSA-9p56-p6mw-w8qc · BIT-jenkins-2025-67635 · CVE-2025-67635

Published · Modified

Description

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

Ready to move

Start Securing

Free, no credit card | First findings in minutes