CVE-2026-59869 – Bitbucket

CVSS 7.5 IMPORTANT Zero Day – Immediate Deployment

“Dependency weaknesses can turn routine data processing into security bypasses, memory exhaustion, and application compromise.”

Bitbucket is affected by nine dependency vulnerabilities covering request manipulation, prototype hijacking, resource exhaustion, unsafe buffer handling, and path-control bypass. CVE-2026-41907 has a CVSS score of 8.1, High severity. CVE-2026-12143, CVE-2026-46625, CVE-2026-69152, CVE-2026-55831, CVE-2026-56819, CVE-2026-59869, CVE-2026-48779, and CVE-2026-6321 each have a CVSS score of 7.5, High severity.

Public proof-of-concept information is available for eight of the vulnerabilities. Impact includes manipulated multipart requests and cookies, CPU and memory exhaustion, HTTP/2 and WebSocket denial of service, unsafe buffer writes, and URI normalization weaknesses that can bypass path-based controls.

Key Details

Affected Product
Nodeca Js-yaml
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-407
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.