CVE-2026-103497: SSRF
Published Oct 1, 2026
·Updated
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
Affected Software
2 affected components
JetBrains YouTrack<2026.2.19422
JetBrains YouTrack<2026.2.19422
Event History
Oct 1, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges and can exploit it remotely without user interaction.
2
Are deployments using the GitHub VCS integration affected?
YouTrack versions before 2026.2.19422 are affected where the GitHub VCS integration can be used. The provided data does not state whether the integration is enabled by default.
3
What is the available remediation?
Upgrade JetBrains YouTrack to version 2026.2.19422 or later. The issue is identified as fixed in versions before that release.