ENISA EUVD · EUVD-2026-36524Official EUVD mappingform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.
Official EUVD record ↗BSI · German · WID-SEC-2026-3623IBM DataPower Gateway: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen, einen Denial-of-Service-Zustand auszulösen oder Cross-Site-Scripting-Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3376Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-2488IBM App Connect Enterprise: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗INCIBE-CERT · Spanish · boletin-de-seguridad-de-atlassian-agosto-de-2026Boletín de seguridad de Atlassian: agosto de 20263.10 (LTS) Data Center Only;
10.3.24 (LTS) Data Center Only.
Jira Service Management Data Center y Server:
11.3.10 (LTS) Data Center Only;
10.3.24 (LTS) Data Center Only.
Detalle
Las vulnerabilidades críticas publicadas en este boletín pertenecen a componentes de terceros. Se trata de vulnerabilidades en dependencias que no pertenecen a Atlassian. La aplicación de estas dependencias por parte de Atlassian presenta un riesgo menor, no crítico, según la evaluación realizada.
A continuación, se detallan las vulnerabilidades de severidad alta que afectan a Atlassian:
CVE-2026-14682: RCE (Remote Code Execution) en org.bouncycastle:bcprov-jdk18on.
CVE-2026-12143: RCE (Remote Code Execution) en form-data.
CVE-2026-58059: DoS (Denial of Service) en org.bouncycastle:bcprov-jdk18on.
CVE-2026-12802: Fallo criptográfico en org.bouncycastle:bcpkix-jdk18on.
CVE-2026-58060: RCE (Remote Code Execution) en org.bouncycastle:bcprov-jdk18on.
CVE-2026-12803: Fallo criptográfico en org.bouncycastle:bcprov-jdk18on.
CVE-2026-13506: DoS (Denial of Service) en org.bouncycastle:bcprov-jdk18on.
CVE-2026-56745: DoS (Denial of Service) en io.netty:netty-codec-http.
CVE-2026-59639: Fallo criptográfico en org.bouncycastle:bcpkix-jdk18on.
CVE-2026-12816: Fallo criptográfico en org.bouncycastle:bcprov-jdk18on.
CVE-2026-59901:
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMrd?id=CVE-2026-0636
Référence CVE CVE-2026-10723
https://www.cve.org/CVERecord?id=CVE-2026-10723
Référence CVE CVE-2026-10805
https://www.cve.org/CVERecord?id=CVE-2026-10805
Référence CVE CVE-2026-11622
https://www.cve.org/CVERecord?id=CVE-2026-11622
Référence CVE CVE-2026-11721
https://www.cve.org/CVERecord?id=CVE-2026-11721
Référence CVE CVE-2026-11822
https://www.cve.org/CVERecord?id=CVE-2026-11822
Référence CVE CVE-2026-11824
https://www.cve.org/CVERecord?id=CVE-2026-11824
Référence CVE CVE-2026-11940
https://www.cve.org/CVERecord?id=CVE-2026-11940
Référence CVE CVE-2026-11979
https://www.cve.org/CVERecord?id=CVE-2026-11979
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-12185
https://www.cve.org/CVERecord?id=CVE-2026-12185
Référence CVE CVE-2026-12590
https://www.cve.org/CVERecord?id=CVE-2026-12590
Référence CVE CVE-2026-12802
https://www.cve.org/CVERecord?id=CVE-2026-12802
Référence CVE CVE-2026-12803
https://www.cve.org/CVERecord?id=CVE-2026-12803
Référence CVE CVE-2026-12816
https://www.cve.org/CVERecord?id=CVE-2026-12816
Référence CVE CVE-2026-12860
https://www.cve.org/CVERecord?id=CVE-2026-12860
Référence CVE CVE-2026-13149
https://www.cve.org/CVERecord?id=CVE-2026-13149
Référence CVE CVE-2026-13204
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-10842
Référence CVE CVE-2026-11331
https://www.cve.org/CVERecord?id=CVE-2026-11331
Référence CVE CVE-2026-11541
https://www.cve.org/CVERecord?id=CVE-2026-11541
Référence CVE CVE-2026-11548
https://www.cve.org/CVERecord?id=CVE-2026-11548
Référence CVE CVE-2026-11549
https://www.cve.org/CVERecord?id=CVE-2026-11549
Référence CVE CVE-2026-11622
https://www.cve.org/CVERecord?id=CVE-2026-11622
Référence CVE CVE-2026-11721
https://www.cve.org/CVERecord?id=CVE-2026-11721
Référence CVE CVE-2026-11722
https://www.cve.org/CVERecord?id=CVE-2026-11722
Référence CVE CVE-2026-11897
https://www.cve.org/CVERecord?id=CVE-2026-11897
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-12243
https://www.cve.org/CVERecord?id=CVE-2026-12243
Référence CVE CVE-2026-12617
https://www.cve.org/CVERecord?id=CVE-2026-12617
Référence CVE CVE-2026-13204
https://www.cve.org/CVERecord?id=CVE-2026-13204
Référence CVE CVE-2026-13321
https://www.cve.org/CVERecord?id=CVE-2026-13321
Référence CVE CVE-2026-14257
https://www.cve.org/CVERecord?id=CVE-2026-14257
Référence CVE CVE-2026-14742
https://www.cve.org/CVERecord?id=CVE-2026-14742
Référence CVE CVE-2026-14981
https://www.cve.org/CVERecord?id=CVE-2026-14981
Référence CVE CVE-2026-15057
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-10571
Référence CVE CVE-2026-10649
https://www.cve.org/CVERecord?id=CVE-2026-10649
Référence CVE CVE-2026-10842
https://www.cve.org/CVERecord?id=CVE-2026-10842
Référence CVE CVE-2026-10852
https://www.cve.org/CVERecord?id=CVE-2026-10852
Référence CVE CVE-2026-11541
https://www.cve.org/CVERecord?id=CVE-2026-11541
Référence CVE CVE-2026-11546
https://www.cve.org/CVERecord?id=CVE-2026-11546
Référence CVE CVE-2026-11714
https://www.cve.org/CVERecord?id=CVE-2026-11714
Référence CVE CVE-2026-11806
https://www.cve.org/CVERecord?id=CVE-2026-11806
Référence CVE CVE-2026-11897
https://www.cve.org/CVERecord?id=CVE-2026-11897
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-12185
https://www.cve.org/CVERecord?id=CVE-2026-12185
Référence CVE CVE-2026-12590
https://www.cve.org/CVERecord?id=CVE-2026-12590
Référence CVE CVE-2026-12802
https://www.cve.org/CVERecord?id=CVE-2026-12802
Référence CVE CVE-2026-12803
https://www.cve.org/CVERecord?id=CVE-2026-12803
Référence CVE CVE-2026-12816
https://www.cve.org/CVERecord?id=CVE-2026-12816
Référence CVE CVE-2026-12860
https://www.cve.org/CVERecord?id=CVE-2026-12860
Référence CVE CVE-2026-13006
https://www.cve.org/CVERecord?id=CVE-2026-13006
Référence CVE CVE-2026-13149
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-10051
Référence CVE CVE-2026-10535
https://www.cve.org/CVERecord?id=CVE-2026-10535
Référence CVE CVE-2026-10842
https://www.cve.org/CVERecord?id=CVE-2026-10842
Référence CVE CVE-2026-10846
https://www.cve.org/CVERecord?id=CVE-2026-10846
Référence CVE CVE-2026-10879
https://www.cve.org/CVERecord?id=CVE-2026-10879
Référence CVE CVE-2026-11525
https://www.cve.org/CVERecord?id=CVE-2026-11525
Référence CVE CVE-2026-11541
https://www.cve.org/CVERecord?id=CVE-2026-11541
Référence CVE CVE-2026-11806
https://www.cve.org/CVERecord?id=CVE-2026-11806
Référence CVE CVE-2026-11897
https://www.cve.org/CVERecord?id=CVE-2026-11897
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-12151
https://www.cve.org/CVERecord?id=CVE-2026-12151
Référence CVE CVE-2026-12243
https://www.cve.org/CVERecord?id=CVE-2026-12243
Référence CVE CVE-2026-12413
https://www.cve.org/CVERecord?id=CVE-2026-12413
Référence CVE CVE-2026-12505
https://www.cve.org/CVERecord?id=CVE-2026-12505
Référence CVE CVE-2026-13149
https://www.cve.org/CVERecord?id=CVE-2026-13149
Référence CVE CVE-2026-13311
https://www.cve.org/CVERecord?id=CVE-2026-13311
Référence CVE CVE-2026-13676
https://www.cve.org/CVERecord?id=CVE-2026-13676
Référence CVE CVE-2026-14380
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1032Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-10534
Référence CVE CVE-2026-10535
https://www.cve.org/CVERecord?id=CVE-2026-10535
Référence CVE CVE-2026-10543
https://www.cve.org/CVERecord?id=CVE-2026-10543
Référence CVE CVE-2026-10695
https://www.cve.org/CVERecord?id=CVE-2026-10695
Référence CVE CVE-2026-11541
https://www.cve.org/CVERecord?id=CVE-2026-11541
Référence CVE CVE-2026-11546
https://www.cve.org/CVERecord?id=CVE-2026-11546
Référence CVE CVE-2026-11714
https://www.cve.org/CVERecord?id=CVE-2026-11714
Référence CVE CVE-2026-11806
https://www.cve.org/CVERecord?id=CVE-2026-11806
Référence CVE CVE-2026-11906
https://www.cve.org/CVERecord?id=CVE-2026-11906
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-14525
https://www.cve.org/CVERecord?id=CVE-2026-14525
Référence CVE CVE-2026-16243
https://www.cve.org/CVERecord?id=CVE-2026-16243
Référence CVE CVE-2026-16439
https://www.cve.org/CVERecord?id=CVE-2026-16439
Référence CVE CVE-2026-16441
https://www.cve.org/CVERecord?id=CVE-2026-16441
Référence CVE CVE-2026-16956
https://www.cve.org/CVERecord?id=CVE-2026-16956
Référence CVE CVE-2026-18499
https://www.cve.org/CVERecord?id=CVE-2026-18499
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMCVERecord?id=CVE-2025-68160
Référence CVE CVE-2025-68161
https://www.cve.org/CVERecord?id=CVE-2025-68161
Référence CVE CVE-2025-69418
https://www.cve.org/CVERecord?id=CVE-2025-69418
Référence CVE CVE-2025-7338
https://www.cve.org/CVERecord?id=CVE-2025-7338
Référence CVE CVE-2025-7783
https://www.cve.org/CVERecord?id=CVE-2025-7783
Référence CVE CVE-2026-0636
https://www.cve.org/CVERecord?id=CVE-2026-0636
Référence CVE CVE-2026-0994
https://www.cve.org/CVERecord?id=CVE-2026-0994
Référence CVE CVE-2026-10536
https://www.cve.org/CVERecord?id=CVE-2026-10536
Référence CVE CVE-2026-11856
https://www.cve.org/CVERecord?id=CVE-2026-11856
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-12590
https://www.cve.org/CVERecord?id=CVE-2026-12590
Référence CVE CVE-2026-13149
https://www.cve.org/CVERecord?id=CVE-2026-13149
Référence CVE CVE-2026-13311
https://www.cve.org/CVERecord?id=CVE-2026-13311
Référence CVE CVE-2026-14446
https://www.cve.org/CVERecord?id=CVE-2026-14446
Référence CVE CVE-2026-14512
https://www.cve.org/CVERecord?id=CVE-2026-14512
Référence CVE CVE-2026-14515
https://www.cve.org/CVERecord?id=CVE-2026-14515
Référence CVE CVE-2026-14528
https://www.cve.org/CVERecord?id=CVE-2026-14528
Référence CVE CVE-2026-14529
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0933Multiples vulnérabilités dans les produits IBMord?id=CVE-2025-68161
Référence CVE CVE-2026-0636
https://www.cve.org/CVERecord?id=CVE-2026-0636
Référence CVE CVE-2026-10852
https://www.cve.org/CVERecord?id=CVE-2026-10852
Référence CVE CVE-2026-11383
https://www.cve.org/CVERecord?id=CVE-2026-11383
Référence CVE CVE-2026-11536
https://www.cve.org/CVERecord?id=CVE-2026-11536
Référence CVE CVE-2026-11541
https://www.cve.org/CVERecord?id=CVE-2026-11541
Référence CVE CVE-2026-11594
https://www.cve.org/CVERecord?id=CVE-2026-11594
Référence CVE CVE-2026-11707
https://www.cve.org/CVERecord?id=CVE-2026-11707
Référence CVE CVE-2026-11897
https://www.cve.org/CVERecord?id=CVE-2026-11897
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-15057
https://www.cve.org/CVERecord?id=CVE-2026-15057
Référence CVE CVE-2026-2004
https://www.cve.org/CVERecord?id=CVE-2026-2004
Référence CVE CVE-2026-2005
https://www.cve.org/CVERecord?id=CVE-2026-2005
Référence CVE CVE-2026-2006
https://www.cve.org/CVERecord?id=CVE-2026-2006
Référence CVE CVE-2026-22731
https://www.cve.org/CVERecord?id=CVE-2026-22731
Référence CVE CVE-2026-22732
https://www.cve.org/CVERecord?id=CVE-2026-22732
Référence CVE CVE-2026-22733
https://www.cve.org/CVERecord?id=CVE-2026-22733
Référence CVE CVE-2026-24281
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiané Atlassian JSWSERVER-26873 du 21 juillet 2026
https://jira.atlassian.com/browse/JSWSERVER-26873
Référence CVE CVE-2022-37599
https://www.cve.org/CVERecord?id=CVE-2022-37599
Référence CVE CVE-2022-37601
https://www.cve.org/CVERecord?id=CVE-2022-37601
Référence CVE CVE-2022-37603
https://www.cve.org/CVERecord?id=CVE-2022-37603
Référence CVE CVE-2025-11226
https://www.cve.org/CVERecord?id=CVE-2025-11226
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-62718
https://www.cve.org/CVERecord?id=CVE-2025-62718
Référence CVE CVE-2025-69873
https://www.cve.org/CVERecord?id=CVE-2025-69873
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-21577
https://www.cve.org/CVERecord?id=CVE-2026-21577
Référence CVE CVE-2026-21579
https://www.cve.org/CVERecord?id=CVE-2026-21579
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-29145
https://www.cve.org/CVERecord?id=CVE-2026-29145
Référence CVE CVE-2026-29146
https://www.cve.org/CVERecord?id=CVE-2026-29146
Référence CVE CVE-2026-33671
https://www.cve.org/CVERecord?id=CVE-2026-33671
Référence CVE CVE-2026-34043
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMord?id=CVE-2025-68470
Référence CVE CVE-2025-69873
https://www.cve.org/CVERecord?id=CVE-2025-69873
Référence CVE CVE-2025-71176
https://www.cve.org/CVERecord?id=CVE-2025-71176
Référence CVE CVE-2026-0540
https://www.cve.org/CVERecord?id=CVE-2026-0540
Référence CVE CVE-2026-10535
https://www.cve.org/CVERecord?id=CVE-2026-10535
Référence CVE CVE-2026-10842
https://www.cve.org/CVERecord?id=CVE-2026-10842
Référence CVE CVE-2026-11595
https://www.cve.org/CVERecord?id=CVE-2026-11595
Référence CVE CVE-2026-11708
https://www.cve.org/CVERecord?id=CVE-2026-11708
Référence CVE CVE-2026-11712
https://www.cve.org/CVERecord?id=CVE-2026-11712
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-14501
https://www.cve.org/CVERecord?id=CVE-2026-14501
Référence CVE CVE-2026-21441
https://www.cve.org/CVERecord?id=CVE-2026-21441
Référence CVE CVE-2026-21860
https://www.cve.org/CVERecord?id=CVE-2026-21860
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22008
https://www.cve.org/CVERecord?id=CVE-2026-22008
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenThe form-data library up to version 4.0.5 is vulnerable to CRLF injection due to unescaped carriage return, line feed, and double-quote characters in multipart field names and filenames, fixed in versions 2.5.6, 3.0.5, and 4.0.6 by escaping these characters.
Official advisory ↗