Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - August 18 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
  • CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
  • CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly
  • CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
  • CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
  • CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
  • CVE-2026-3505Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
  • CVE-2026-40983Micrometer gRPC server instrumentation DoS vulnerability
  • CVE-2026-0603Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
  • CVE-2026-54513jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
  • CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
  • CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
  • CVE-2026-40984Micrometer HTTP server instrumentations DoS vulnerability
  • CVE-2026-13676fast-uri vulnerable to host confusion via failed IDN canonicalization
  • CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  • CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  • CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  • CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
  • CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
  • CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunks
  • CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  • CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
  • CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
  • CVE-2026-12151undici WebSocket client vulnerable to denial of service via fragment count bypass
  • CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  • CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
  • CVE-2026-27606Rollup 4 has Arbitrary File Write via Path Traversal
  • CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig
  • CVE-2026-6321fast-uri vulnerable to path traversal via percent-encoded dot segments
  • CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
  • CVE-2026-6322fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  • CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
  • CVE-2026-29786node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
  • CVE-2026-21582This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center
  • CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
  • CVE-2026-10050Digest authentication lossy encoding
  • CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read
  • CVE-2026-69152brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
  • CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapter
  • CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify
  • CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names
  • CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption
  • CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
  • CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split
  • CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard
  • CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs present
  • CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signers
  • CVE-2026-18446fast-uri vulnerable to host confusion via backslash authority introducer
  • CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
  • CVE-2026-55685React Router: Unauthenticated Denial of Service via Inefficient Route Matching

Source and provenance

Original title: Security Bulletin - August 18 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗