Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - September 15 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
  • CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
  • CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
  • CVE-2026-45674Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
  • CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
  • CVE-2026-47691Netty has Insufficient Bailiwick Validation for NS Records
  • CVE-2026-54513jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
  • CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
  • CVE-2026-13676fast-uri vulnerable to host confusion via failed IDN canonicalization
  • CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
  • CVE-2026-68763Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
  • CVE-2026-75899fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
  • CVE-2026-75975fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
  • CVE-2026-76172fast-uri vulnerable to host confusion via percent-encoded scheme normalization
  • CVE-2026-73566node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
  • CVE-2026-75140jsoup Uncontrolled Resource Consumption in XmlTreeBuilder
  • CVE-2026-21582This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center
  • CVE-2026-75595Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
  • CVE-2026-67214nanoid Infinite Loop via Negative Size in non-secure module
  • CVE-2026-73646PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
  • CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
  • CVE-2026-73088Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
  • CVE-2026-73089Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
  • CVE-2026-73086nanoid: Integer Overflow or Wraparound
  • CVE-2026-67213nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom
  • CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read
  • CVE-2026-69152brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
  • CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapter
  • CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify
  • CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names
  • CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption
  • CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
  • CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split
  • CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard
  • CVE-2026-59650MTI/A0 DH agreement exponentiates unvalidated peer value
  • CVE-2026-8763Name Constraints bypass via trailing dot in rfc822Name and URI
  • CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs present
  • CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signers
  • CVE-2026-18446fast-uri vulnerable to host confusion via backslash authority introducer
  • CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
  • CVE-2026-45623PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
  • CVE-2026-14257brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
  • CVE-2026-55831Netty SPDY SETTINGS frame count materializes unbounded settings map
  • CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
  • CVE-2026-56745Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
  • CVE-2026-55833Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
  • CVE-2026-16221fast-uri vulnerable to host confusion via literal backslash authority delimiter
  • CVE-2026-48801linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
  • CVE-2026-59869js-yaml: YAML merge-key chains can force quadratic CPU consumption
  • CVE-2026-59887linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

Source and provenance

Original title: Security Bulletin - September 15 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗