BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - September 15 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
- CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
- CVE-2026-45674Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
- CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
- CVE-2026-47691Netty has Insufficient Bailiwick Validation for NS Records
- CVE-2026-54513jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
- CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
- CVE-2026-13676fast-uri vulnerable to host confusion via failed IDN canonicalization
- CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
- CVE-2026-68763Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
- CVE-2026-75899fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
- CVE-2026-75975fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
- CVE-2026-76172fast-uri vulnerable to host confusion via percent-encoded scheme normalization
- CVE-2026-73566node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
- CVE-2026-75140jsoup Uncontrolled Resource Consumption in XmlTreeBuilder
- CVE-2026-21582This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center
- CVE-2026-75595Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
- CVE-2026-67214nanoid Infinite Loop via Negative Size in non-secure module
- CVE-2026-73646PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
- CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
- CVE-2026-73088Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
- CVE-2026-73089Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
- CVE-2026-73086nanoid: Integer Overflow or Wraparound
- CVE-2026-67213nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom
- CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read
- CVE-2026-69152brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
- CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapter
- CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify
- CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names
- CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption
- CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
- CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split
- CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard
- CVE-2026-59650MTI/A0 DH agreement exponentiates unvalidated peer value
- CVE-2026-8763Name Constraints bypass via trailing dot in rfc822Name and URI
- CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs present
- CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signers
- CVE-2026-18446fast-uri vulnerable to host confusion via backslash authority introducer
- CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
- CVE-2026-45623PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
- CVE-2026-14257brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
- CVE-2026-55831Netty SPDY SETTINGS frame count materializes unbounded settings map
- CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
- CVE-2026-56745Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
- CVE-2026-55833Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
- CVE-2026-16221fast-uri vulnerable to host confusion via literal backslash authority delimiter
- CVE-2026-48801linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
- CVE-2026-59869js-yaml: YAML merge-key chains can force quadratic CPU consumption
- CVE-2026-59887linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
Source and provenance
Original title: Security Bulletin - September 15 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗