Intel

AIKIDO-2026-606077

performance is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-84670 Published Today

88

High Risk

This Affects:

JAVAperformance
0.0.1 - 1015
Fixed in 1017
Are you affected? Scan for Free

TL;DR

Performance Plugin deserializes cached performance reports from build directories using Java serialization without restricting classes. An attacker with Item/Configure permission can place crafted serialized data that executes code on the Jenkins controller during report loading. The fix removes deserialization of cached performance reports.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Item/Configure permission can influence cached performance report files on the controller.

Background info

performance is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 1015.

How to fix this

Upgrade the org.jenkins-ci.plugins:performance library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform