HomeDefault status
affected
2.541 (maven) before *
unaffected
2.528.3 (maven) before 2.528.*
unaffected
Description
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
Product status
2.541 (maven) before *
2.528.3 (maven) before 2.528.*
References
www.jenkins.io/security/advisory/2025-12-10/ (Jenkins Security Advisory 2025-12-10)