CVE-2026-33002 is a high-severity DNS rebinding vulnerability affecting Jenkins versions 2.442 through 2.554 and LTS 2.426.3 through 2.541.2. This flaw allows attackers to bypass origin validation for CLI WebSocket endpoint requests by manipulating Host or X-Forwarded-Host headers. Rated 7.5 HIGH, the vulnerability requires high attack complexity and user interaction but can lead to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with a very low EPSS score indicating minimal observed risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.426.3, < 2.541.3CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
>= 2.442, < 2.555CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.