Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.main/jenkins-core
  4. ›
  5. CVE-2025-59476

CVE-2025-59476: Jenkins has a log message injection vulnerability

September 17, 2025 (updated November 5, 2025)

In Jenkins 2.527 and earlier, LTS 2.516.2 and earlier, the log formatter that prepares log messages for console output (including jenkins.log and equivalent) does not restrict or transform the characters that can be inserted from user-specified content in log messages.

This allows attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

Jenkins 2.528, LTS 2.516.3 adds an indicator at the beginning of a line that was inserted as part of log message content: [CR], [LF], or [CRLF] (representing the kind of line break), followed by > .

References

  • github.com/advisories/GHSA-qrh5-jg98-cr48
  • github.com/jenkinsci/jenkins
  • nvd.nist.gov/vuln/detail/CVE-2025-59476
  • www.jenkins.io/security/advisory/2025-09-17/

Code Behaviors & Features

Detect and mitigate CVE-2025-59476 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.516.3, all versions starting from 2.517 before 2.528

Fixed versions

  • 2.516.3
  • 2.528

Solution

Upgrade to versions 2.516.3, 2.528 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-117: Improper Output Neutralization for Logs
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Source file

maven/org.jenkins-ci.main/jenkins-core/CVE-2025-59476.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:20:56 +0000.