BlackTreeCVE IntelligenceOfficial source evidenceconfluence.atlassian.comVersioned article
Official source article · confluence.atlassian.com
Security Bulletin - April 21 2026 | Atlassian Support | Atlassian Documentation
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherconfluence.atlassian.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 20:00 UTC
Linked CVEs26
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-33870Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-33871Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
- CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig
- CVE-2026-29063Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
- CVE-2026-22029React Router vulnerable to XSS via Open Redirects
- CVE-2026-24842node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
- CVE-2026-23745node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
- CVE-2026-23950node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
- CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
- CVE-2025-48734Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
- CVE-2026-21571This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center
- CVE-2026-24880Apache Tomcat: Request smuggling via invalid chunk extension
- CVE-2026-31802node-tar Symlink Path Traversal via Drive-Relative Linkpath
- CVE-2026-26960node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
- CVE-2026-25547Uncontrolled Resource Consumption in @isaacs/brace-expansion
- CVE-2024-29371In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio
- CVE-2025-66020Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
- CVE-2024-47875DOMPurify nesting-based mXSS
- CVE-2022-1471Remote Code execution in SnakeYAML
- CVE-2022-25927Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function
- CVE-2023-1370Stack exhaustion in json-smart leads to denial of service when parsing malformed JSON
- CVE-2023-3635Okio GzipSource unhandled exception Denial of Service
- CVE-2024-45801Tampering by prototype polution in DOMPurify
- CVE-2021-31597n/a — Improper Certificate Validation
- CVE-2021-0341In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto
- CVE-2023-48631Denial of Service of regular expression in package @adobe/css-tools
Source and provenance
Original title: Security Bulletin - April 21 2026 | Atlassian Support | Atlassian Documentation. Captured 27 Sept 2026, 20:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗