Impact
The vulnerability is an instance of a decompression bomb that can be supplied through the import endpoint of JetBrains YouTrack. An attacker can submit a specially crafted compressed file that causes the server to allocate excessive resources during decompression, leading to a denial of service. The weakness is classified as CWE-409, a logic flaw that allows an attacker to exhaust system resources.
Affected Systems
JetBrains YouTrack versions prior to 2026.2.18177 are affected. The vulnerability exists in the import functionality that accepts compressed files from users.
Risk and Exploitability
With a CVSS score of 6.5 the risk is medium. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The likely attack vector is remote, accessible through the import endpoint, and requires the ability to upload a compressed file.
OpenCVE Enrichment