Improper resource shutdown or release in Jenkins and Jenkins LTS - CVE-2025-67635
Published: December 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected application does not properly close HTTP-based CLI connections when the connection stream becomes corrupted. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
How to mitigate CVE-2025-67635
Jenkins LTS - update to 2.528.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins and Jenkins LTS
- Red Hat OpenShift Developer Tools 4.13 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.14 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.15 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.12 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.17 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.16 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.19 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.18 update for Openshift Jenkins
- Red Hat OpenShift Developer Tools 4.20 update for Openshift Jenkins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function