Description
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in JetBrains YouTrack's handling of PSD files. A crafted PSD attachment can trigger an unexpected loop or resource exhaustion, causing the application to become unresponsive and deny service to legitimate users. This leads to a denial‑of‑service condition, potentially affecting the availability of the issue‑tracking functionality. The weakness is classified as CWE‑835, which involves an infinite loop or termination error.

Affected Systems

Any instance of JetBrains YouTrack running a pre‑2026.2.19422 build is susceptible. The affected product is JetBrains YouTrack, and all versions before the 2026.2.19422 release are vulnerable. Updating to 2026.2.19422 or later removes the flaw.

Risk and Exploitability

The CVSS score is 6.5, indicating a medium severity. No EPSS value is available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited. The attack likely requires an attacker to supply a malicious PSD file through the web interface or message ingestion. Successful exploitation would disrupt service availability but does not directly compromise data confidentiality or integrity. The lack of exploitation evidence lowers risk but the medium severity calls for remediation.

Generated by OpenCVE AI on October 1, 2026 at 10:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to YouTrack 2026.2.19422 or newer, which contains the fix for PSD attachment processing.
  • Temporarily disable PSD attachment uploads in the YouTrack administration settings until the upgrade is applied.
  • Ensure that no untrusted subscription or message feed allows PSD files to be uploaded until the application is patched.

Generated by OpenCVE AI on October 1, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted PSD Attachments in JetBrains YouTrack

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-10-01T13:37:00.137Z

Reserved: 2026-09-30T17:07:13.897Z

Link: CVE-2026-103492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T10:17:14.657

Modified: 2026-10-01T12:41:25.413

Link: CVE-2026-103492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:15:05Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')