Jenkins Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2021-21607
Jenkins 2.274 and earlier LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs allowing attackers to request crafted URLs that use all available memory in Jenkins potentially leading to out of memory errors.