Known Vulnerabilities for Bitbucket by Atlassian
Listed below are 10 of the newest known vulnerabilities associated with "Bitbucket" by "Atlassian".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72872 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bit... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-72867 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-456... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-58370 json | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, p... | Not Provided | 2026-06-30 | 2026-07-14 |
| CVE-2026-57289 json | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname va... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-48924 json | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-12225 json | syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnera... | Not Provided | 2026-06-16 | 2026-06-21 |
| CVE-2026-3515 json | A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attac... | Not Provided | 2026-05-24 | 2026-05-26 |
| CVE-2022-43781 json | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with ... | 9.8 - CRITICAL | 2022-11-17 | 2022-11-18 |
| CVE-2022-36804 json | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before v... | 8.8 - HIGH | 2022-08-25 | 2023-08-08 |
| CVE-2022-26137 json | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters ... | 8.8 - HIGH | 2022-07-20 | 2022-08-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Bitbucket | 7.3.1 | |||
| Application | Atlassian | Bitbucket | 7.2.4 | |||
| Application | Atlassian | Bitbucket | 7.1.1 | |||
| Application | Atlassian | Bitbucket | 7.1.0 | |||
| Application | Atlassian | Bitbucket | 7.0.3 | |||
| Application | Atlassian | Bitbucket | 7.0.2 | |||
| Application | Atlassian | Bitbucket | 7.0.0 | |||
| Application | Atlassian | Bitbucket | 6.9.3 | |||
| Application | Atlassian | Bitbucket | 6.9.2 | |||
| Application | Atlassian | Bitbucket | 6.9.1 | |||
| Application | Atlassian | Bitbucket | 6.9.0 | |||
| Application | Atlassian | Bitbucket | 6.8.4 | |||
| Application | Atlassian | Bitbucket | 6.8.3 | |||
| Application | Atlassian | Bitbucket | 6.8.2 | |||
| Application | Atlassian | Bitbucket | 6.8.0 | |||
| Application | Atlassian | Bitbucket | 6.7.5 | |||
| Application | Atlassian | Bitbucket | 6.7.4 | |||
| Application | Atlassian | Bitbucket | 6.7.3 | |||
| Application | Atlassian | Bitbucket | 6.7.2 | |||
| Application | Atlassian | Bitbucket | 6.7.1 |