Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - March 17 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 08:35 UTC
Linked CVEs15

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-68493Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
  • CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig
  • CVE-2026-22029React Router vulnerable to XSS via Open Redirects
  • CVE-2026-24842node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
  • CVE-2026-23745node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
  • CVE-2026-23950node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
  • CVE-2026-21884React Router SSR XSS in ScrollRestoration
  • CVE-2026-21570This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center
  • CVE-2025-64775Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)
  • CVE-2025-64756glob CLI: Command injection via -c/--cmd executes matches with shell:true
  • CVE-2022-25927Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function
  • CVE-2024-57699When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS)
  • CVE-2022-25883Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range
  • CVE-2023-52428n/a — Allocation of Resources Without Limits or Throttling
  • CVE-2020-28469Regular Expression Denial of Service (ReDoS)

Source and provenance

Original title: Security Bulletin - March 17 2026 | Atlassian Support | Atlassian Documentation. Captured 28 Sept 2026, 08:35 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗