CVE Database
/

CVE-2026-33002

Back to search

CVE-2026-33002

Published: Mar 18, 2026

Modified: Mar 19, 2026

PUBLISHED

Description

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.

VendorProductVersions

Jenkins Project

Jenkins

unaffected
0 - < 2.426.3
unaffected
2.427 - < 2.442
unaffected
2.555 - < *
unaffected
2.541.3 - < 2.541.*

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now