Known Vulnerabilities for IntelliJ IDEA by JetBrains
Listed below are 10 of the newest known vulnerabilities associated with "IntelliJ IDEA" by "JetBrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86505 json | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86504 json | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-le... | Not Provided | 2026-09-07 | 2026-09-09 |
| CVE-2026-86503 json | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fet... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86502 json | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code executi... | Not Provided | 2026-09-07 | 2026-09-09 |
| CVE-2026-86501 json | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-75058 json | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75057 json | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75056 json | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75055 json | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75054 json | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | Not Provided | 2026-08-17 | 2026-08-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Intellij Idea | 9.0.4 | |||
| Application | Jetbrains | Intellij Idea | 9.0.3 | |||
| Application | Jetbrains | Intellij Idea | 2020.3 | |||
| Application | Jetbrains | Intellij Idea | 2020.2 | |||
| Application | Jetbrains | Intellij Idea | 2020.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.0 | |||
| Application | Jetbrains | Intellij Idea | 2019.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.1 | |||
| Application | Jetbrains | Intellij Idea | 2018.3.6 |