CVE-2026-14336Patch

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://[email protected] (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attacker controls. An unauthenticated caller of POST /v1/upload/sbom can use this to force PIA to make outbound HTTP(S) requests to an arbitrary attacker-chosen host, and to have oidc.verify_token accept a JWT signed with the attacker's own key.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-05: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-05: 107-05
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Merge News@mergenewsapp
    Patch

    Critical Jenkins OIDC flaw (CVE-2026-14336) allows unauthenticated SSRF attacks, risking CI/CD pipeline compromise. Patch now. #jenkins #security #cve #oidc

    Post summary

    The post highlights a critical Jenkins OIDC flaw (CVE-2026-14336) that allows unauthenticated SSRF attacks, and it reports that a patch is currently available.

    0000038
    24 followersView on X

Explore more