CVE-2026-29063
This High severity Injection vulnerability was introduced in versions 9.0.1, 9.0.3, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Injection vulnerability, with a CVSS Score of 8.7 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N allows an unauthenticated attacker to modify the actions taken by a system call. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.19 * Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.10 See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center from the download center (https://www.atlassian.com/software/confluence/download-archives). The National Vulnerability Database provides the following description for this vulnerability: Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
EPSS 0.08% · 23.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Confluence Data Center |
Exploit Intelligence
- https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-mvgw (nist-nvd)
- CIRCL seen: CVE-2024-29371 (circl-sighting)
- CIRCL seen: CVE-2024-29371 (circl-sighting)
- CIRCL seen: CVE-2024-29371 (circl-sighting)
- CIRCL seen: CVE-2024-29371 (circl-sighting)
- CIRCL seen: CVE-2024-29371 (circl-sighting)
- https://bitbucket.org/b_c/jose4j/issues/220/vuln-zip-bomb-attack (circl)
- CIRCL seen: CVE-2026-29063 (circl-sighting)
- CIRCL seen: CVE-2026-29063 (circl-sighting)
- CIRCL seen: CVE-2026-29063 (circl-sighting)
…and 63 more exploits
Timeline
- Jun 28, 2021 PoC Published
- Dec 17, 2025 PoC Published
- Dec 17, 2025 PoC Published
- Jan 21, 2026 PoC Published
- Feb 25, 2026 PoC Published
- Feb 25, 2026 PoC Published
- Mar 4, 2026 CVE Published
- Mar 6, 2026 PoC Published
- Mar 6, 2026 PoC Published
- Mar 7, 2026 EPSS Score
- Mar 8, 2026 EPSS Score
- Mar 9, 2026 EPSS Score