Known vulnerabilities in Pipeline: Groovy Libraries

Vendor: Jenkins
Software CPE: cpe:2.3:a:jenkins:pipeline_groovy_libraries:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 6.1

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Pipeline: Groovy Libraries Pipeline: Groovy Libraries is affected by 3 known vulnerabilities: 1 medium, 2 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150928 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-92131
CWE-22 Low
No
No
806.v408277b_33d1d 18.09.2026 SB20260918134
#VU147207 - Cross-Site Request Forgery (CSRF)
CVE-2026-84663
CWE-352 Low
No
No
805.va_fc79344957d 07.09.2026 SB2026090705
#VU132683 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-48921
CWE-59 Medium
No
No
798.v5cc688825312 28.05.2026 SB20260528281