CVE-2026-100254: JetBrains TeamCity
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
Affected products
- JetBrains TeamCity: before 2025.11.8 (fixed in 2025.11.8); from 2026.1, before 2026.1.4 (fixed in 2026.1.4)
Published 2026-09-30. Last modified 2026-10-06.