ZeroHour

CVE-2026-84655

CVSS 3.1
4.3 medium
EPSS
<1%p9
Published
()
Modified
Description

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

Vendors
jenkins
Products
jenkins
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.