BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - January 20 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs25
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2024-21538Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
- CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
- CVE-2025-48989Apache Tomcat: h2 DoS - Made You Reset
- CVE-2025-54988Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
- CVE-2025-66516Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
- CVE-2025-15284arrayLimit bypass in bracket notation allows DoS via memory exhaustion
- CVE-2026-21569This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server
- CVE-2025-64775Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)
- CVE-2025-12383Race Condition allows Bypass of Trust Restrictions
- CVE-2025-55163Netty MadeYouReset HTTP/2 DDoS Vulnerability
- CVE-2025-53689Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons
- CVE-2025-52434Apache Tomcat: APR/Native Connector crash leading to DoS
- CVE-2024-38286Apache Tomcat: Denial of Service
- CVE-2025-48976Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
- CVE-2025-9288Missing type checks leading to hash rewind and passing on crafted data
- CVE-2025-9287Missing type checks leading to hash rewind and passing on crafted data
- CVE-2025-41249CVE-2025-41249: Spring Framework Annotation Detection Vulnerability
- CVE-2025-52999jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data
- CVE-2025-49146pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
- CVE-2022-45693Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter
- CVE-2025-27152Possible SSRF and Credential Leakage via Absolute URL in axios Requests
- CVE-2024-45296path-to-regexp outputs backtracking regular expressions
- CVE-2022-25883Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range
- CVE-2024-45801Tampering by prototype polution in DOMPurify
- CVE-2021-3807Inefficient Regular Expression Complexity in chalk/ansi-regex
Source and provenance
Original title: Security Bulletin - January 20 2026 | Atlassian Support | Atlassian Documentation. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗