BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - July 21 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
- CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
- CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM.
- CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly
- CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
- CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
- CVE-2026-42581Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
- CVE-2026-33870Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-33871Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
- CVE-2026-27830c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
- CVE-2025-69873ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled
- CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
- CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
- CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
- CVE-2026-45736ws: Uninitialized memory disclosure
- CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
- CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
- CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunks
- CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
- CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
- CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
- CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
- CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
- CVE-2026-29063Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
- CVE-2026-6321fast-uri vulnerable to path traversal via percent-encoded dot segments
- CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
- CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
- CVE-2026-42044Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
- CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
- CVE-2026-6322fast-uri vulnerable to host confusion via percent-encoded authority delimiters
- CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
- CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- CVE-2026-29146Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
- CVE-2026-21575This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows
- CVE-2026-21579This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center
- CVE-2026-21577This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center
- CVE-2026-47838Unauthorized User Impersonation when Using X.509 Client Certificates
- CVE-2025-11226Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino
- CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
- CVE-2026-44490Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
- CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
- CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
- CVE-2026-42585Netty: HTTP Request Smuggling due to malformed Transfer-Encoding
- CVE-2026-42583Netty: Lz4FrameDecoder resource exhaustion
- CVE-2026-42035Axios: Header Injection via Prototype Pollution
- CVE-2026-29145Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Source and provenance
Original title: Security Bulletin - July 21 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗