Sceawere

Vulnerability Detail

CVE-2026-75050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetBrains YouTrack Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
5h ago
Vendor
JetBrains
Product
YouTrack
Attack Type
CWE-770
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-17T16:17:52.097Z",
  "pubdate": "2026-08-17T16:17:52.097Z",
  "executiveSummary": "A denial of service vulnerability exists in JetBrains YouTrack before versions 2026.1.13901 and 2026.2.17950. The vulnerability allows an attacker to trigger a denial of service condition within the application through the submission of specially crafted type parameters. This security flaw impacts the overall availability of the affected YouTrack deployments, potentially disrupting critical issue tracking and project management operations. The risk implication is centered on service degradation or complete application unresponsiveness, which can severely hinder organizational workflows. Attackers capable of interacting with the targeted YouTrack instance can exploit this vulnerability without complex prerequisites, provided they can transmit the malicious input containing the crafted type parameters. Exploitation leverages improper handling of specific type definitions by the underlying parsing or processing logic, leading to resource exhaustion or application crashes. Remediation requires updating the software to the patched versions specified by the vendor to ensure proper input validation and resource management.",
  "technicalDetails": "The vulnerability resides within the input processing mechanisms of JetBrains YouTrack, specifically in the component responsible for parsing and evaluating type parameters. When the application encounters maliciously crafted type parameters supplied by a user, the internal parsing routines fail to adequately validate, bound, or sanitize the input structure. This improper input handling triggers computational inefficiencies, excessive memory allocation, or unbounded recursion during the type resolution phase. The root cause is an algorithmic complexity issue or lack of strict depth and resource limits when processing complex or malformed type declarations. The attack flow begins when an attacker crafts a specific payload embedded within HTTP requests containing the malicious type parameters and transmits them across the network to the exposed YouTrack endpoint. Upon receipt, the vulnerable component parses the payload, causing severe CPU spikes, memory exhaustion, or thread starvation as the application attempts to resolve the anomalous structures. Consequently, the Java Virtual Machine or the application worker threads become unresponsive, leading to a denial of service for legitimate users. Authentication and privilege requirements depend on the specific endpoint exposed to the input vector, but the vulnerability effectively compromises system availability upon successful delivery of the payload. The affected versions include all JetBrains YouTrack deployments prior to 2026.1.13901 and 2026.2.17950. Post-exploitation impact is limited to service disruption and application downtime rather than arbitrary code execution or data exfiltration, but it critically impairs business continuity."
}
CVE-2026-75050: JetBrains YouTrack Denial of Service (HIGH Severity, CVSS: 7.1) - Sceawere