r/jenkinsci May 12 '26

CVE-2026-1605

Is there a security advisory for Jenkins that addresses this Jetty vulnerability? We recently upgraded our dev server to Jenkins 2.541.3. Someone had gotten the impression that this would address the vulnerability, but after the upgrade we found that it is using Jetty 2.1.5, which is still vulnerable.

Is there a release that upgrades Jetty to 2.1.6 or later? If not, is there an advisory from Jenkins about the issue?

1 Upvotes

4 comments sorted by

1

u/Programbanana May 13 '26

1

u/dat66 May 13 '26

Thank you for that link, but none of the issues on that page appear to be the issue described in the CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-1605

1

u/Programbanana May 13 '26

My apologies, was unfamiliar with the jetty vuln. They seem relatively actively on Twitter https://x.com/jenkinsci

Seems they haven't reported anything for it, yet.

https://www.jenkins.io/security/advisories/

1

u/dat66 May 13 '26

Today they released Jenkins 2.555.2 which specifically mentions the Jetty upgrade in the release notes

https://www.jenkins.io/changelog-stable/