CVE-2026-42523
published 2026-04-29CVE-2026-42523: Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook…
PriorityP343critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.28%
20.0th percentile
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials_binding | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | github | < 1.46.0.1 | 1.46.0.1 |
| jenkins | github | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source_plugin | — | — |
| jenkins | github_plugin | — | — |
| jenkins | html_publisher | — | — |
| jenkins | html_publisher_plugin | — | — |
| jenkins | matrix_authorization_strategy | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | script_security | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins_project | jenkins_github_plugin | <= 1.46.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Jenkins GitHub Plugin up to 1.46.0 cross site scripting (EUVD-2026-26225 / Nessus ID 310885)
vuldb·2026-04-29·CVSS 9.0
CVE-2026-42523 [CRITICAL] Jenkins GitHub Plugin up to 1.46.0 cross site scripting (EUVD-2026-26225 / Nessus ID 310885)
A vulnerability, which was classified as problematic, has been found in Jenkins GitHub Plugin up to 1.46.0. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-42523. The attack can be initiated remotely. There is not any exploit available.
GHSA
Jenkins GitHub Plugin has an XSS vulnerability
ghsa·2026-04-29
CVE-2026-42523 [CRITICAL] CWE-79 Jenkins GitHub Plugin has an XSS vulnerability
Jenkins GitHub Plugin has an XSS vulnerability
In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
GitHub Plugin 1.46.0.1 no longer processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".
Jenkins
Jenkins Security Advisory 2026-04-29
vendor_jenkins·2026-04-29·CVSS 4.3
CVE-2026-42519 [MEDIUM] Jenkins Security Advisory 2026-04-29
Title: Jenkins Security Advisory 2026-04-29
Jenkins Security Advisory 2026-04-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Credentials Binding
Plugin
GitHub
Plugin
GitHub Branch Source
Plugin
HTML Publisher
Plugin
Matrix Authorization Strategy
Plugin
Microsoft Entra ID (previously Azure AD)
No detection rules found.
No public exploits indexed.
2026-04-29
Published