CVE-2025-67635

HIGH

Jenkins < 2.528.3 - Improper Resource Release

Title source: rule
STIX 2.1

Description

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (4)
jenkins/jenkins < 2.528.3
jenkins/jenkins < 2.541
org.jenkins-ci.main/cli 2.529 - 2.541Maven
org.jenkins-ci.main/jenkins-core 2.529 - 2.541Maven
Published Dec 10, 2025
Tracked Since Feb 18, 2026