Known Vulnerabilities for products from Jenkins
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jenkins".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53442 json | Not Provided | 2026-06-10 | 2026-06-10 | |
| CVE-2026-53441 json | Not Provided | 2026-06-10 | 2026-06-10 | |
| CVE-2026-53440 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet cont... | Not Provided | 2026-06-10 | 2026-06-12 |
| CVE-2026-53439 json | Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission ... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-53438 json | A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-53437 json | Not Provided | 2026-06-10 | 2026-06-10 | |
| CVE-2026-53436 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately poin... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-53435 json | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary typ... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-48927 json | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48926 json | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing a... | Not Provided | 2026-05-27 | 2026-06-02 |
| CVE-2026-48924 json | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48923 json | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, all... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48922 json | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48921 json | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared librar... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48920 json | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting ... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48919 json | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48918 json | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-48917 json | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | Not Provided | 2026-05-27 | 2026-06-02 |
| CVE-2026-48916 json | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. | Not Provided | 2026-05-27 | 2026-06-02 |
| CVE-2026-42525 json | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL afte... | Not Provided | 2026-04-29 | 2026-05-05 |
Known software with vulnerabilities from Jenkins
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jenkins | 360 Fireline | 1.0 |
| Application | Jenkins | Absint Astree | 1.0.0 |
| Application | Jenkins | Active Choices | 0.1 |
| Application | Jenkins | Active Directory | 1.0 |
| Application | Jenkins | Alauda Devops Pipeline | 2.3.2 |
| Application | Jenkins | Alauda Kubernetes Support | 2.0.0 |
| Application | Jenkins | Amazon Ec2 | 1.0 |
| Application | Jenkins | Amazon Sns Build Notifier | - |
| Application | Jenkins | Amazon Web Services Serverless Application Model | 1.2.2 |
| Application | Jenkins | Amazon Web Services Service Application Model | 1.2.2 |
| Application | Jenkins | Anchore Container Image Scanner | 1.0.0 |
| Application | Jenkins | Android Lint | 1.0 |
| Application | Jenkins | Ansible | 0.1 |
| Application | Jenkins | Ansible Tower | 0.5.0 |
| Application | Jenkins | Appdynamics | 1.0.0 |
| Application | Jenkins | Applatix | - |
| Application | Jenkins | Appspider | 1.0.12 |
| Application | Jenkins | Aqua Microscanner | 1.0.0 |
| Application | Jenkins | Aqua Security Scanner | - |
| Application | Jenkins | Aqua Security Severless Scanner | 1.0.0 |