Executive brief
JetBrains YouTrack is an issue-tracking and project-management system used by development teams to collaborate on tasks and defects. A decompression bomb vulnerability in the import endpoint allows an attacker to cause a denial-of-service (DoS) condition by uploading a specially crafted compressed file, making the system temporarily unavailable for legitimate users and disrupting team workflow.
Technical details
This is a decompression bomb vulnerability (also known as a zip bomb) in the file import endpoint of JetBrains YouTrack. The vulnerability exists because the import functionality fails to validate or limit the decompression ratio of uploaded compressed files before processing them. An attacker can craft a highly-compressed malicious archive that, when decompressed, consumes excessive CPU and memory resources, causing a denial-of-service condition. No authentication bypass or data exposure is involved; the impact is availability-focused. The vulnerability affects YouTrack versions before 2026.2.18177 and has been patched in that version and later.
Affected products
- JetBrains YouTrack before 2026.2.18177
Timeline
- 2026-08-17: disclosed
- 2026-02: patched: Fixed in version 2026.2.18177