io.jenkins.plugins:pipeline-groovy-lib vulnerabilities
CVEs whose affected-version data names the io.jenkins.plugins:pipeline-groovy-lib package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-57284Medium· 4.3Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types
Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types
▾ Sunlitjenkins · io.jenkins.plugins:pipeline-groovy-libEPSS 0.34%via GHSA
CVE-2026-57283Medium· 4.3Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
▾ Sunlitjenkins · io.jenkins.plugins:pipeline-groovy-libEPSS 0.24%via GHSA