JetBrains TeamCity
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*
- < 2026.1
- < 2025.11.5
A vulnerability allowing unauthenticated server-side request forgery (SSRF) has been identified in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5. This vulnerability was made possible through the build status feature, which could be exploited to send requests to internal services or resources, potentially leading to unauthorized information disclosure or manipulation.
Exploitation of this vulnerability could result in unauthorized access to internal services or resources, allowing for potential information disclosure or manipulation.
Users can upgrade to TeamCity versions 2026.1 or 2025.11.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.