High severityOSV Advisory· Published Dec 10, 2025· Updated Dec 16, 2025
CVE-2025-67635
CVE-2025-67635
Description
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | >= 2.529, < 2.541 | 2.541 |
org.jenkins-ci.main:cliMaven | >= 2.529, < 2.541 | 2.541 |
org.jenkins-ci.main:jenkins-coreMaven | < 2.528.3 | 2.528.3 |
org.jenkins-ci.main:cliMaven | < 2.528.3 | 2.528.3 |
Affected products
8- Range: 1.324-rc, 1.325-rc, 1.327-rc, …
- osv-coords7 versionspkg:apk/chainguard/jenkins-2.516pkg:apk/chainguard/jenkins-2.516-openjdk-17pkg:apk/chainguard/jenkins-2.516-openjdk-21pkg:apk/chainguard/jenkins-2.528pkg:bitnami/jenkinspkg:maven/org.jenkins-ci.main/clipkg:maven/org.jenkins-ci.main/jenkins-core
< 2.516.3-r4+ 6 more
- (no CPE)range: < 2.516.3-r4
- (no CPE)range: < 2.516.3-r4
- (no CPE)range: < 2.516.3-r4
- (no CPE)range: < 2.528.3-r2
- (no CPE)range: < 2.528.3
- (no CPE)range: >= 2.529, < 2.541
- (no CPE)range: >= 2.529, < 2.541
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-9p56-p6mw-w8qcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-67635ghsaADVISORY
- www.jenkins.io/security/advisory/2025-12-10/ghsavendor-advisoryWEB
- fluidattacks.com/blog/unauth-dos-in-jenkins-clighsaWEB
- github.com/jenkinsci/jenkins/commit/efa1816322026f2b9235a27eee814bcc7ba0a764ghsaWEB
News mentions
1- Jenkins Security Advisory 2025-12-10Jenkins Security Advisories · Dec 10, 2025