GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishing

CVE-2026-53437Control plane, storage & DevOpscurated

Impact

Jenkins treats a redirect URL as pointing back at itself when tab or newline characters sit between the two slashes, so a crafted login link can send a user to an attacker-controlled site immediately after they authenticate. The flaw gives no code execution and no access to build agents by itself; its value to an attacker is harvesting Jenkins credentials or tokens from a user who believes they are still on the controller. On a GPU fleet the Jenkins credentials store commonly holds registry, cluster, and cloud credentials, so a successful phish against a Jenkins user is worth more than the 4.3 score implies. Affects Jenkins 2.567 and earlier and LTS 2.555.2 and earlier.

Who can reach it

Anyone who can get a Jenkins user to click a crafted link to the controller. The victim must be able to reach the Jenkins login page and must interact; no attacker authentication is required.

What to do

Upgrade the controller past the affected range per the 2026-06-10 Jenkins advisory (the record states 2.567 and earlier and LTS 2.555.2 and earlier are affected but does not name the fixed version here). Red Hat has shipped errata for OpenShift Developer Tools and Services 4.12 through 4.18. Upgrading means restarting the controller, so drain or pause running builds first; agents and GPU nodes are untouched.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.