Official source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com

Security Bulletin - May 19 2026 | Atlassian Support | Atlassian Documentation

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 08:30 UTC
Linked CVEs24

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM.
  • CVE-2025-67030Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642
  • CVE-2026-27830c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
  • CVE-2026-27727mchange-commons-java: Remote Code Execution via JNDI Reference Resolution
  • CVE-2026-42198pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
  • CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig
  • CVE-2026-22029React Router vulnerable to XSS via Open Redirects
  • CVE-2026-29786node-tar: Hardlink Path Traversal via Drive-Relative Linkpath
  • CVE-2026-29146Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
  • CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
  • CVE-2026-29062jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
  • CVE-2026-39304Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
  • CVE-2026-34483Apache Tomcat: Incomplete escaping of JSON access logs
  • CVE-2026-24880Apache Tomcat: Request smuggling via invalid chunk extension
  • CVE-2026-29145Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
  • CVE-2026-29129Apache Tomcat: TLS cipher order is not preserved
  • CVE-2026-34487Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
  • CVE-2026-22732Under Some Conditions Spring Security HTTP Headers Are not Written
  • CVE-2026-33750brace-expansion: Zero-step sequence causes process hang and memory exhaustion
  • CVE-2026-31802node-tar Symlink Path Traversal via Drive-Relative Linkpath
  • CVE-2026-26960node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
  • CVE-2023-24998Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts
  • CVE-2025-52999jackson-core Has Potential for StackoverflowError if user parses an input file that contains very deeply nested data
  • CVE-2024-45801Tampering by prototype polution in DOMPurify

Source and provenance

Original title: Security Bulletin - May 19 2026 | Atlassian Support | Atlassian Documentation. Captured 27 Sept 2026, 08:30 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗