Views
2

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

Jira Software 11.3.5 was released on 2026-05-06. It addresses multiple Data Center security issues, including XSS, DoS, file inclusion, security misconfiguration, and missing security headers, plus several bug fixes.

Update Details

Security

  • Security misconfiguration in Jira Software Data Center (JSWSERVER-26793).
  • DOM-based XSS in Jira Software Data Center (JSWSERVER-26788).
  • Denial of service issues in Jira Software Data Center (JSWSERVER-26787, JSWSERVER-26782).
  • File inclusion issues in Jira Software Data Center (JSWSERVER-26786, JSWSERVER-26781).
  • Security headers omission in Jira Software Data Center (JSWSERVER-26785).
  • Improper encoding in org.apache.tomcat:tomcat-catalina dependency in Jira Software Data Center (JSWSERVER-26780).

Bug Fixes

  • Fixed a regression caused by the JSWSERVER-26702 fix affecting JSWSERVER-26536.
  • Restored digital signatures for JSM/JSW OBR files required for Jira 11.x Data Center.
  • Resolved cache timeout and token timeout interaction issues affecting the dvcs plugin and Bitbucket Cloud accounts.
  • Fixed Advanced Roadmaps Import and Export pages not loading.
  • Resolved InvalidDocumentFieldException during reindexing or issue operations in Jira Data Center.
  • Stopped excessive access log spam from repeated GET /rest/api/2/search/error/lookup- requests.
  • Fixed Backlog Complete Sprint form field instruction association.

Hints

  • Release date: 2026-05-06.
  • This release is for Jira Software Data Center 11.3.5.
Product Information

Vendor: Atlassian

Product: Service Management

Version: 11.3.5

Release date: May 6, 2026