CVE-2026-100267: Medium severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
Affected Software
Event History
Frequently Asked Questions
Which YouTrack deployments are exposed?
JetBrains YouTrack versions before 2026.2.19197 are affected when mailbox regex mail-rule filters are used. The provided information does not establish whether such filters are enabled by default.
What does an attacker need to do to exploit this issue?
The issue is remotely reachable and requires no privileges or user interaction, but exploitation has high attack complexity. It involves triggering excessive regular-expression processing through mailbox mail-rule filters, resulting in a denial of service.
What is the impact of a successful attack?
A successful reDoS attack can affect availability. The provided CVSS vector indicates no confidentiality or integrity impact.
How can I remediate the issue?
Upgrade JetBrains YouTrack to version 2026.2.19197 or later. If upgrading cannot be done immediately, review use of mailbox regex mail-rule filters, since they are the affected feature.