Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - January 20 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs25

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2024-21538Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
  • CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
  • CVE-2025-48989Apache Tomcat: h2 DoS - Made You Reset
  • CVE-2025-54988Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
  • CVE-2025-66516Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
  • CVE-2025-15284arrayLimit bypass in bracket notation allows DoS via memory exhaustion
  • CVE-2026-21569This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server
  • CVE-2025-64775Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)
  • CVE-2025-12383Race Condition allows Bypass of Trust Restrictions
  • CVE-2025-55163Netty MadeYouReset HTTP/2 DDoS Vulnerability
  • CVE-2025-53689Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons
  • CVE-2025-52434Apache Tomcat: APR/Native Connector crash leading to DoS
  • CVE-2024-38286Apache Tomcat: Denial of Service
  • CVE-2025-48976Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
  • CVE-2025-9288Missing type checks leading to hash rewind and passing on crafted data
  • CVE-2025-9287Missing type checks leading to hash rewind and passing on crafted data
  • CVE-2025-41249CVE-2025-41249: Spring Framework Annotation Detection Vulnerability
  • CVE-2025-52999jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data
  • CVE-2025-49146pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
  • CVE-2022-45693Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter
  • CVE-2025-27152Possible SSRF and Credential Leakage via Absolute URL in axios Requests
  • CVE-2024-45296path-to-regexp outputs backtracking regular expressions
  • CVE-2022-25883Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range
  • CVE-2024-45801Tampering by prototype polution in DOMPurify
  • CVE-2021-3807Inefficient Regular Expression Complexity in chalk/ansi-regex

Source and provenance

Original title: Security Bulletin - January 20 2026 | Atlassian Support | Atlassian Documentation. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗