Vulnerability Description
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-70437?
CVE-2026-70437 is a vulnerability with a CVSS score of 3.7 (LOW). Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token a...
How severe is CVE-2026-70437?
CVE-2026-70437 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-70437?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.