BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - August 18 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
- CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification
- CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly
- CVE-2026-48043netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- CVE-2026-45416Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
- CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
- CVE-2026-3505Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
- CVE-2026-40983Micrometer gRPC server instrumentation DoS vulnerability
- CVE-2026-0603Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
- CVE-2026-54513jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
- CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names
- CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-40984Micrometer HTTP server instrumentations DoS vulnerability
- CVE-2026-13676fast-uri vulnerable to host confusion via failed IDN canonicalization
- CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
- CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
- CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
- CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
- CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunks
- CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios
- CVE-2026-12143form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
- CVE-2026-12151undici WebSocket client vulnerable to denial of service via fragment count bypass
- CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
- CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
- CVE-2026-27606Rollup 4 has Arbitrary File Write via Path Traversal
- CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig
- CVE-2026-6321fast-uri vulnerable to path traversal via percent-encoded dot segments
- CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
- CVE-2026-6322fast-uri vulnerable to host confusion via percent-encoded authority delimiters
- CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
- CVE-2026-29786node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
- CVE-2026-21582This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center
- CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
- CVE-2026-10050Digest authentication lossy encoding
- CVE-2026-14682Possible OOM from unbounded up-front allocation on a definite-length read
- CVE-2026-69152brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
- CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapter
- CVE-2026-58060HSS public-key level count unbounded, enabling huge allocation on verify
- CVE-2026-58059Quadratic-time escaping when stringifying X.500 distinguished names
- CVE-2026-12802CMS AuthEnvelopedData fails to enforce tag-length on decryption
- CVE-2026-12803KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
- CVE-2026-12816IESEngine stream-mode MAC forgery via length-dependent KDF split
- CVE-2026-13506Lazy ASN.1 sequence forcing resets nesting-depth guard
- CVE-2026-59642CMS AuthenticatedData content not bound to MAC when authAttrs present
- CVE-2026-59639CMS verifySignatures returns true for SignedData with zero signers
- CVE-2026-18446fast-uri vulnerable to host confusion via backslash authority introducer
- CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
- CVE-2026-55685React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Source and provenance
Original title: Security Bulletin - August 18 2026 | Atlassian Support | Atlassian Documentation. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗