CVE-2025-64134: Jenkins Jdepend

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected products

  • Jenkins Jdepend: up to and including 1.3.1

Published 2025-10-29. Last modified 2026-10-08.