CVE-2025-32754(jenkins / ssh-agent)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ssh-agent

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ssh-agent

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
By indicator
Full discourse1 post
  • Tech At Bloomberg@TechAtBloomberg

    @dns43 @PurdueEngineers @torresariass This isn't theoretical. Software Dark Matter led to 3 zero-days: a leaked GitHub push token baked into the popular https://bloom.bg/4ee6jMc Docker image (CVE-2025-32111) + static, reused SSH host keys in Jenkins' ssh-agent image (CVE-2025-32754/-32755) #SupplyChainSecurity (3/5) https://t.co/kU8G6D4Trz

    1000026
    19.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsssh-agent-docker-

Explore more