
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75047 is a denial-of-service vulnerability in JetBrains YouTrack caused by improper handling of decompression bombs at the import endpoint. It affects all YouTrack versions before 2026.2.18177 and was disclosed on August 17, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-409 (Improper Handling of Highly Compressed Data / Data Amplification). An authenticated attacker with low privileges can upload a specially crafted compressed file — a "decompression bomb" — to YouTrack's import endpoint. When the server attempts to decompress the file, it expands to an extremely large size, exhausting system memory or CPU resources and causing the application to crash or become unresponsive. No complex preconditions are required beyond having a valid low-privilege account (GitHub Advisory).
Successful exploitation results in a denial-of-service condition, making the YouTrack instance unavailable to all users. The impact is limited to availability — there is no confidentiality or integrity compromise. Because YouTrack is a project management and issue-tracking platform, an outage could disrupt development workflows and team collaboration for the duration of the attack (GitHub Advisory, JetBrains).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, though any authenticated low-privilege user could theoretically attempt it (GitHub Advisory).
JetBrains has released a fix in YouTrack version 2026.2.18177; upgrading to this version or later is the primary recommended remediation (JetBrains, GitHub Advisory). As interim workarounds, administrators should implement network-level rate limiting and enforce file size restrictions on import endpoints. Restricting import functionality to trusted or administrative users only can further reduce the attack surface.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."