VYPR
High severityOSV Advisory· Published Dec 10, 2025· Updated Dec 16, 2025

CVE-2025-67635

CVE-2025-67635

Description

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.main:jenkins-coreMaven
>= 2.529, < 2.5412.541
org.jenkins-ci.main:cliMaven
>= 2.529, < 2.5412.541
org.jenkins-ci.main:jenkins-coreMaven
< 2.528.32.528.3
org.jenkins-ci.main:cliMaven
< 2.528.32.528.3

Affected products

8

Patches

Vulnerability mechanics

References

5

News mentions

1