CVE-2026-53437 Details
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.
An open redirect vulnerability has been identified in Jenkins versions through 2.567 and LTS 2.555.2. This vulnerability arises because the application improperly validates redirect URLs after login, particularly in the 'Delegate to servlet container' security realm. URLs containing tab or newline characters between '//' are not correctly sanitized, allowing attackers to redirect users to malicious domains. Exploitation of this vulnerability could lead to phishing attacks.
Users should update to Jenkins version 2.568 or LTS 2.555.3, both of which include the necessary fix. Instructions for updating can be found on the Jenkins website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:60239 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60246 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60247 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60248 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60249 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60250 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60251 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60252 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60254 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60256 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:60259 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-53437 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487544 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53437.json | redhat-SADP | |
| https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3711+3755 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | redhat-SADP |
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins jenkins | < 2.555.3 < 2.568 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |