CVE-2026-84655CWE-116

CVE-2026-84655

Medium · published September 2, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
8.9
In the wild
Unconfirmed
What it is

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00192 · 8.9th percentile
Weakness
CWE-116 · Improper Encoding or Escaping of Output
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing…
    cvelistv5