CVE-2026-67214
This High severity DoS (Denial of Service) vulnerability known as CVE-2026-67214 was introduced in 10.0.0 and later of Jira Software Data Center and Server. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.2 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT: P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Jira Software Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Jira Software Data Center and Server 11.3: Upgrade to a release greater than or equal to 11.3.11 * Jira Software Data Center and Server 10.3: Upgrade to a release greater than or equal to 10.3.25 See the release notes ([https://www.atlassian.com/software/jira/download-archives]). You can download the latest version of Jira Software Data Center and Server from the download center ([https://www.atlassian.com/software/jira/download-archives]). The National Vulnerability Database provides the following description for this vulnerability: nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
EPSS 0.33% · 26.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Software Data Center | |
| Atlassian | Crowd Data Center |
Timeline
- Jul 29, 2026 CVE Published
- Jul 29, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 13, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 26, 2026 CVE Updated
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score