Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - July 21 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
  • CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
  • CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM.
  • CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly
  • CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
  • CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
  • CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
  • CVE-2026-42581Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
  • CVE-2026-33870Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
  • CVE-2026-33871Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
  • CVE-2026-27830c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
  • CVE-2025-69873ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled
  • CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
  • CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
  • CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  • CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  • CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  • CVE-2026-45736ws: Uninitialized memory disclosure
  • CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
  • CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
  • CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunks
  • CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  • CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
  • CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
  • CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
  • CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  • CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
  • CVE-2026-29063Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
  • CVE-2026-6321fast-uri vulnerable to path traversal via percent-encoded dot segments
  • CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
  • CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
  • CVE-2026-42044Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
  • CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  • CVE-2026-6322fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  • CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
  • CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
  • CVE-2026-29146Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
  • CVE-2026-21575This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows
  • CVE-2026-21579This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center
  • CVE-2026-21577This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center
  • CVE-2026-47838Unauthorized User Impersonation when Using X.509 Client Certificates
  • CVE-2025-11226Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino
  • CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
  • CVE-2026-44490Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
  • CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
  • CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
  • CVE-2026-42585Netty: HTTP Request Smuggling due to malformed Transfer-Encoding
  • CVE-2026-42583Netty: Lz4FrameDecoder resource exhaustion
  • CVE-2026-42035Axios: Header Injection via Prototype Pollution
  • CVE-2026-29145Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled

Source and provenance

Original title: Security Bulletin - July 21 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗