DNS Rebinding Affecting org.jenkins-ci.main:jenkins-core package, versions [2.426.3,2.427)[2.442,2.555)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIMAIN-15700544
  • published20 Mar 2026
  • disclosed18 Mar 2026
  • creditTallowX92, Babauca

Introduced: 18 Mar 2026

CVE-2026-33002  (opens in a new tab)
CWE-346  (opens in a new tab)
CWE-350  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.main:jenkins-core to version 2.427, 2.555 or higher.

Overview

org.jenkins-ci.main:jenkins-core is an open source automation server.

Affected versions of this package are vulnerable to DNS Rebinding in the origin validation process for WebSocket CLI requests due to reliance on the Host or X-Forwarded-Host HTTP headers. An attacker can bypass origin validation by exploiting DNS rebinding techniques, potentially gaining unauthorized access to sensitive operations.

CVSS Base Scores

version 4.0
version 3.1