Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-57289

CVE-2026-57289_CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connectio...

Jenkins Project Jenkins Bitbucket Push and Pull Request Plugin CVE
LOW 3.7 CVE-2026-57288

CVE-2026-57288_CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI...

Jenkins Project Jenkins Active Directory Plugin CVE
MEDIUM 4.3 CVE-2026-57287

CVE-2026-57287_CVE-2026-57287

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historica...

Jenkins Project Jenkins Job Configuration History Plugin CVE
MEDIUM 4.3 CVE-2026-57286

CVE-2026-57286_CVE-2026-57286

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain info...

Jenkins Project Jenkins Git Parameter Plugin CVE
MEDIUM 4.3 CVE-2026-57285

CVE-2026-57285_CVE-2026-57285

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission...

Jenkins Project Jenkins GitHub Branch Source Plugin CVE
MEDIUM 4.3 CVE-2026-57284

CVE-2026-57284_CVE-2026-57284

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Ge...

Jenkins Project Jenkins Pipeline: Groovy Plugin CVE
MEDIUM 4.3 CVE-2026-57283

CVE-2026-57283_CVE-2026-57283

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate...

Jenkins Project Jenkins Pipeline: Groovy Plugin CVE
MEDIUM 5 CVE-2026-57282

CVE-2026-57282_CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper...

Jenkins Project Jenkins Git client Plugin CVE
HIGH 7.5 CVE-2026-57281

CVE-2026-57281_CVE-2026-57281

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, ...

Jenkins Project Jenkins Script Security Plugin CVE
HIGH 8.8 CVE-2026-57280

CVE-2026-57280_CVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each ...

Jenkins Project Jenkins Script Security Plugin CVE