Back to search
CVE-2026-33002
Published: Mar 18, 2026
Modified: Mar 19, 2026
PUBLISHED
Description
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins | unaffected 0 - < 2.426.3unaffected 2.427 - < 2.442unaffected 2.555 - < *unaffected 2.541.3 - < 2.541.* |
References
Jenkins Security Advisory 2026-03-18
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now