CVE-2026-75047
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-75047 is a denial-of-service vulnerability in JetBrains YouTrack caused by improper handling of decompression bombs at the import endpoint. It affects all YouTrack versions before 2026.2.18177 and was disclosed on August 17, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).

Technical details

The vulnerability is classified as CWE-409 (Improper Handling of Highly Compressed Data / Data Amplification). An authenticated attacker with low privileges can upload a specially crafted compressed file — a "decompression bomb" — to YouTrack's import endpoint. When the server attempts to decompress the file, it expands to an extremely large size, exhausting system memory or CPU resources and causing the application to crash or become unresponsive. No complex preconditions are required beyond having a valid low-privilege account (GitHub Advisory).

Impact

Successful exploitation results in a denial-of-service condition, making the YouTrack instance unavailable to all users. The impact is limited to availability — there is no confidentiality or integrity compromise. Because YouTrack is a project management and issue-tracking platform, an outage could disrupt development workflows and team collaboration for the duration of the attack (GitHub Advisory, JetBrains).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, though any authenticated low-privilege user could theoretically attempt it (GitHub Advisory).

Exploitation steps

  1. Obtain low-privilege credentials: Acquire or register a valid YouTrack account with at least basic authenticated access.
  2. Craft a decompression bomb: Create a malicious compressed archive (e.g., a ZIP or gzip file) that expands to an extremely large size upon decompression — commonly achieved by compressing large amounts of repeated data (e.g., a multi-gigabyte file of null bytes compressed to a few kilobytes).
  3. Identify the import endpoint: Navigate to or directly target YouTrack's import functionality endpoint, which accepts compressed file uploads.
  4. Upload the malicious file: Submit the decompression bomb to the import endpoint via an authenticated HTTP request.
  5. Trigger DoS: The server decompresses the file, consuming excessive memory or CPU resources, causing YouTrack to crash or become unresponsive to all users (GitHub Advisory).

Indicators of compromise

  • Network: Unusual large or repeated POST requests to YouTrack's import endpoint from a single authenticated user account.
  • Logs: Application logs showing decompression errors, out-of-memory exceptions, or abrupt service termination correlated with import endpoint activity.
  • Process: Sudden spike in memory or CPU consumption by the YouTrack server process immediately following an import request; JVM heap exhaustion errors in YouTrack logs.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.2.18177; upgrading to this version or later is the primary recommended remediation (JetBrains, GitHub Advisory). As interim workarounds, administrators should implement network-level rate limiting and enforce file size restrictions on import endpoints. Restricting import functionality to trusted or administrative users only can further reduce the attack surface.

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-62422CRITICAL9.8
  • YouTrack logoYouTrack
  • youtrack
NoYesJul 14, 2026
CVE-2026-75048HIGH8.2
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesAug 17, 2026
CVE-2026-75051HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesAug 17, 2026
CVE-2026-75047MEDIUM6.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesAug 17, 2026
CVE-2026-75046MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management