Junglewise Threat Intelligence

CVE-2026-75050: JetBrains YouTrack DoS attack via crafted type parameters

CVE-2026-75050 · Severity: high · CVSS 7.1 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project management and issue tracking platform used by development teams to manage work and collaborate. An attacker could craft malicious type parameters to trigger a denial-of-service (DoS) attack, rendering the platform unavailable to legitimate users and preventing teams from accessing critical project data and workflows.

Technical details

The vulnerability exists in JetBrains YouTrack's type parameter handling, where insufficient input validation allows an attacker to craft specially formed type parameters that trigger a denial-of-service condition. The vulnerability is reachable via network request without requiring authentication. By sending carefully crafted requests with malicious type parameters, an attacker can exhaust server resources (CPU, memory, or connections), causing the application to become unresponsive. The vulnerability has been patched in YouTrack versions 2026.1.13901 and 2026.2.17950 and later.

Affected products

  • JetBrains YouTrack before 2026.1.13901, before 2026.2.17950

Timeline

  • 2026-08-17: disclosed

References

Related threats