Impact
The vulnerability resides in JetBrains YouTrack's handling of PSD files. A crafted PSD attachment can trigger an unexpected loop or resource exhaustion, causing the application to become unresponsive and deny service to legitimate users. This leads to a denial‑of‑service condition, potentially affecting the availability of the issue‑tracking functionality. The weakness is classified as CWE‑835, which involves an infinite loop or termination error.
Affected Systems
Any instance of JetBrains YouTrack running a pre‑2026.2.19422 build is susceptible. The affected product is JetBrains YouTrack, and all versions before the 2026.2.19422 release are vulnerable. Updating to 2026.2.19422 or later removes the flaw.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. No EPSS value is available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited. The attack likely requires an attacker to supply a malicious PSD file through the web interface or message ingestion. Successful exploitation would disrupt service availability but does not directly compromise data confidentiality or integrity. The lack of exploitation evidence lowers risk but the medium severity calls for remediation.
OpenCVE Enrichment