Skip to content

CVE lookup

CVE-2026-84649

Pruva has a verified reproduction for CVE-2026-84649: Jenkins Stapler: CSRF crumb exposed in dynamically generated JavaScript endpoint (SECURITY-3607). The canonical evidence record is REPRO-2026-00350.

REPRO

REPRO-2026-00350

Package

jenkinsci/jenkins · github

Severity

MEDIUM

Status

published