Server-Side Request Forgery (SSRF) in YouTrack - CVE-2026-103497
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause server-side requests to unintended destinations.
The vulnerability exists due to improper control of request destinations in the GitHub VCS integration when using the integration. A remote attacker can cause the integration to issue requests to unintended destinations to cause server-side requests to unintended destinations.