Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - February 17 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 14:38 UTC
Linked CVEs13

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-48734Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
  • CVE-2025-66516Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
  • CVE-2025-66675Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed
  • CVE-2025-66021OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
  • CVE-2025-48976Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
  • CVE-2025-9287Missing type checks leading to hash rewind and passing on crafted data
  • CVE-2025-59343tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
  • CVE-2025-41249CVE-2025-41249: Spring Framework Annotation Detection Vulnerability
  • CVE-2022-25927Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function
  • CVE-2024-57699When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS)
  • CVE-2022-25883Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range
  • CVE-2020-28469Regular Expression Denial of Service (ReDoS)
  • CVE-2019-20149ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}

Source and provenance

Original title: Security Bulletin - February 17 2026 | Atlassian Support | Atlassian Documentation. Captured 28 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗