Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - June 16 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 02:00 UTC
Linked CVEs45

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
  • CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
  • CVE-2026-42584Netty: HttpClientCodec response desynchronization
  • CVE-2026-42579Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
  • CVE-2026-42581Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
  • CVE-2026-41293Apache Tomcat: HTTP/2 request headers not validated
  • CVE-2026-33870Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
  • CVE-2026-33871Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
  • CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  • CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  • CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  • CVE-2026-45736ws: Uninitialized memory disclosure
  • CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
  • CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  • CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
  • CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
  • CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  • CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
  • CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
  • CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
  • CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
  • CVE-2026-41044Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
  • CVE-2024-22257N/A Spring Security — Missing Authorization
  • CVE-2026-43515Apache Tomcat: Security constraints not correctly applied
  • CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
  • CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
  • CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch
  • CVE-2026-45149brace-expansion: Large numeric range defeats documented `max` DoS protection
  • CVE-2026-42585Netty: HTTP Request Smuggling due to malformed Transfer-Encoding
  • CVE-2026-43512Apache Tomcat: Digest authenticator will authenticate any unknown user
  • CVE-2026-43513Apache Tomcat: LockOutRealm treats user names as case-sensitive
  • CVE-2026-42583Netty: Lz4FrameDecoder resource exhaustion
  • CVE-2026-42498Apache Tomcat: WebSocket authentication header exposure
  • CVE-2026-41284Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
  • CVE-2026-42038Axios: no_proxy bypass via IP alias allows SSRF
  • CVE-2026-42035Axios: Header Injection via Prototype Pollution
  • CVE-2026-29129Apache Tomcat: TLS cipher order is not preserved
  • CVE-2026-34487Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
  • CVE-2026-22732Under Some Conditions Spring Security HTTP Headers Are not Written
  • CVE-2026-27904minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
  • CVE-2026-27903minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
  • CVE-2025-22228CVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password length
  • CVE-2026-26996minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
  • CVE-2019-11272PlaintextPasswordEncoder authenticates encoded passwords that are null
  • CVE-2021-3803Inefficient Regular Expression Complexity in fb55/nth-check

Source and provenance

Original title: Security Bulletin - June 16 2026 | Atlassian Support | Atlassian Documentation. Captured 27 Sept 2026, 02:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗