CVE-2026-103497Medium· 5.5▾ SunlitIn JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100279Medium· 6.5In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100257Medium· 4.3In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-103488High· 7.1In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-103489Low· 2.0In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103490High· 7.2In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103491Medium· 6.5In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues