High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI
ID: 42b3a83c-4934-5f4b-a337-71b0f8454d70
STIX ID: report--42b3a83c-4934-5f4b-a337-71b0f8454d70
Feed Name: cybersecurityNews.com
Threat Score
**Jenkins CVE-2025-67635 — Remote DoS via HTTP CLI:** A high-severity unauthenticated denial-of-service vulnerability in Jenkins (versions 2.540 and earlier; LTS 2.528.2 and earlier) allows remote attackers to send specially crafted HTTP-based CLI requests that corrupt streams and exhaust request-handling threads, rendering servers unresponsive; organizations should upgrade immediately to Jenkins 2.541 or LTS 2.528.3 and monitor for unusual connection/thread activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
