#VU119837 Improper resource shutdown or release in Jenkins and Jenkins LTS - CVE-2025-67635
Published: December 11, 2025
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected application does not properly close HTTP-based CLI connections when the connection stream becomes corrupted. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.