BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - June 16 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 02:00 UTC
Linked CVEs45
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
- CVE-2026-42584Netty: HttpClientCodec response desynchronization
- CVE-2026-42579Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-42581Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
- CVE-2026-41293Apache Tomcat: HTTP/2 request headers not validated
- CVE-2026-33870Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-33871Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
- CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
- CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
- CVE-2026-45736ws: Uninitialized memory disclosure
- CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
- CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
- CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
- CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
- CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
- CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
- CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
- CVE-2026-41044Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
- CVE-2024-22257N/A Spring Security — Missing Authorization
- CVE-2026-43515Apache Tomcat: Security constraints not correctly applied
- CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
- CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
- CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch
- CVE-2026-45149brace-expansion: Large numeric range defeats documented `max` DoS protection
- CVE-2026-42585Netty: HTTP Request Smuggling due to malformed Transfer-Encoding
- CVE-2026-43512Apache Tomcat: Digest authenticator will authenticate any unknown user
- CVE-2026-43513Apache Tomcat: LockOutRealm treats user names as case-sensitive
- CVE-2026-42583Netty: Lz4FrameDecoder resource exhaustion
- CVE-2026-42498Apache Tomcat: WebSocket authentication header exposure
- CVE-2026-41284Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
- CVE-2026-42038Axios: no_proxy bypass via IP alias allows SSRF
- CVE-2026-42035Axios: Header Injection via Prototype Pollution
- CVE-2026-29129Apache Tomcat: TLS cipher order is not preserved
- CVE-2026-34487Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
- CVE-2026-22732Under Some Conditions Spring Security HTTP Headers Are not Written
- CVE-2026-27904minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
- CVE-2026-27903minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- CVE-2025-22228CVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password length
- CVE-2026-26996minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
- CVE-2019-11272PlaintextPasswordEncoder authenticates encoded passwords that are null
- CVE-2021-3803Inefficient Regular Expression Complexity in fb55/nth-check
Source and provenance
Original title: Security Bulletin - June 16 2026 | Atlassian Support | Atlassian Documentation. Captured 27 Sept 2026, 02:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗