Junglewise Threat Intelligence

CVE-2026-75047: JetBrains YouTrack decompression bomb denial of service in import endpoint

CVE-2026-75047 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is an issue-tracking and project-management system used by development teams to collaborate on tasks and defects. A decompression bomb vulnerability in the import endpoint allows an attacker to cause a denial-of-service (DoS) condition by uploading a specially crafted compressed file, making the system temporarily unavailable for legitimate users and disrupting team workflow.

Technical details

This is a decompression bomb vulnerability (also known as a zip bomb) in the file import endpoint of JetBrains YouTrack. The vulnerability exists because the import functionality fails to validate or limit the decompression ratio of uploaded compressed files before processing them. An attacker can craft a highly-compressed malicious archive that, when decompressed, consumes excessive CPU and memory resources, causing a denial-of-service condition. No authentication bypass or data exposure is involved; the impact is availability-focused. The vulnerability affects YouTrack versions before 2026.2.18177 and has been patched in that version and later.

Affected products

  • JetBrains YouTrack before 2026.2.18177

Timeline

  • 2026-08-17: disclosed
  • 2026-02: patched: Fixed in version 2026.2.18177

References

Related threats