Description
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Published: 2026-08-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of a decompression bomb that can be supplied through the import endpoint of JetBrains YouTrack. An attacker can submit a specially crafted compressed file that causes the server to allocate excessive resources during decompression, leading to a denial of service. The weakness is classified as CWE-409, a logic flaw that allows an attacker to exhaust system resources.

Affected Systems

JetBrains YouTrack versions prior to 2026.2.18177 are affected. The vulnerability exists in the import functionality that accepts compressed files from users.

Risk and Exploitability

With a CVSS score of 6.5 the risk is medium. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The likely attack vector is remote, accessible through the import endpoint, and requires the ability to upload a compressed file.

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade YouTrack to version 2026.2.18177 or later to remove the decompression bomb flaw.
  • Configure firewall or access controls to restrict the import endpoint to trusted users or administrative accounts only.
  • If an upgrade cannot be performed immediately, disable the import feature or block large file uploads through application or network policies.
  • Monitor logs for unusually large or repeated upload attempts to detect potential abuse.

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title DoS via Decompression Bomb in YouTrack Import Endpoint

Mon, 17 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-17T16:16:48.386Z

Reserved: 2026-08-17T15:34:07.432Z

Link: CVE-2026-75047

cve-icon Vulnrichment

Updated: 2026-08-17T16:16:42.225Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:51.757

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)