CVE-2026-84655

Published Sep 2, 2026

Last updated 5 days ago

Overview

Description
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.
Source
jenkinsci-cert@googlegroups.com
NVD status
Analyzed
Products
jenkins

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-116

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.