Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2026-06-10

2026-06-10 Jun 10, 2026 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-06-10/. 6 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2026-06-10/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

8 lines
Showing 1–8 of 8
Acknowledgement BR2026-0000-007314 SECURITY-3711 unclaimed
SECURITY-3711
Credited as Takumi Katanoda (SECURITY-3711); Fushuling@secsys from Fudan University and RacerZ@secsys from Fudan University; and, independently, Michael Blunt (SECURITY-3755)
CVE-2026-53440 BR2026-0000-007315 SECURITY-3721 unclaimed
Open redirect vulnerability in "Delegate to servlet container" security realm
Credited as Takumi Katanoda, and, independently, Kartik T Nair (@k0w4lzk1) from Team bi0s
CVE-2026-53435 BR2026-0000-007316 SECURITY-3707 unclaimed
Deserialization vulnerability
Credited as dqh1
CVE-2026-53442 BR2026-0000-007317 SECURITY-3744 unclaimed
Plaintext secrets persisted and served by config.xml endpoints
Credited as quannn
CVE-2026-53442 BR2026-0000-007318 SECURITY-3744 unclaimed
Plaintext secrets persisted and served by config.xml endpoints
Credited as vstxckr
CVE-2026-53439 BR2026-0000-007319 SECURITY-3713 unclaimed
Missing permission checks allow obtaining limited user profile information
Credited as sam91281
CVE-2026-53438 BR2026-0000-007320 SECURITY-3712 unclaimed
Missing permission check allows canceling queue items
Credited as sam91281; and, independently, Aries441
CVE-2026-53441 BR2026-0000-007321 SECURITY-3731 unclaimed
Stored XSS vulnerability in node offline cause description
Credited as wooseokdotkim