CVE-2026-53437: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.
Affected products
- Jenkins Jenkins: before 2.555.3 (fixed in 2.555.3); before 2.568 (fixed in 2.568)
Published 2026-06-10. Last modified 2026-08-27.