Impact
The vulnerability occurs when JetBrains YouTrack versions earlier than 2026.1.13901 or 2026.2.17950 accept specially crafted type parameters, allowing an attacker to exhaust server resources and trigger a denial‑of‑service condition. This flaw is classified under CWE‑770, indicating insufficient resource limits or controls, and results in loss of availability for legitimate users.
Affected Systems
JetBrains YouTrack installations running any version prior to 2026.1.13901 or 2026.2.17950 are affected. Administrators should verify their version and plan an upgrade.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the high severity zone, and the EPSS score is not available, so the probability of exploitation cannot be quantified. It is not listed in the CISA KEV catalog. The likely attack vector involves accessing a network endpoint that processes type parameters, and the vulnerability can be triggered without privileged credentials. Based on the description, it is inferred that the attacker can send crafted requests to generate resource consumption spikes, resulting in service interruption.
OpenCVE Enrichment