JetBrains TeamCity Unauthenticated Server-Side Request Forgery Vulnerability

Vulnerability

A vulnerability allowing unauthenticated server-side request forgery (SSRF) has been identified in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5. This vulnerability was made possible through the build status feature, which could be exploited to send requests to internal services or resources, potentially leading to unauthorized information disclosure or manipulation.

Impact

Exploitation of this vulnerability could result in unauthorized access to internal services or resources, allowing for potential information disclosure or manipulation.

Remediation

Users can upgrade to TeamCity versions 2026.1 or 2025.11.5 to address this vulnerability.

Added: May 29, 2026, 7:31 PM
Updated: May 29, 2026, 7:31 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.