VulnSea

intellij_idea vulnerabilities

CVEs whose affected-version data names the intellij_idea package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-86505Low· 3.3
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

SunlitJetBrains · IntelliJ IDEAEPSS 0.11%via NVD
CVE-2026-86504High· 7.8
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

TwilightJetBrains · IntelliJ IDEAEPSS 0.13%via NVD
CVE-2026-86503Low· 3.3
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

SunlitJetBrains · IntelliJ IDEAEPSS 0.10%via NVD
CVE-2026-86502High· 8.4
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

TwilightJetBrains · IntelliJ IDEAEPSS 0.14%via NVD
CVE-2026-86501Low· 2.8
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

SunlitJetBrains · IntelliJ IDEAEPSS 0.27%via NVD
CVE-2026-75055Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

Sunlitjetbrains · intellij_ideaEPSS 0.12%via NVD
CVE-2026-75057Medium· 6.2
1mo ago

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

Sunlitjetbrains · intellij_ideaEPSS 0.13%via NVD
CVE-2026-75058Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

Sunlitjetbrains · intellij_ideaEPSS 0.12%via NVD
CVE-2026-75054Medium· 6.3
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

Sunlitjetbrains · intellij_ideaEPSS 0.12%via NVD
CVE-2026-75056High· 7.8
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

Twilightjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75053Medium· 5.4
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

Sunlitjetbrains · intellij_ideaEPSS 0.18%via NVD
intellij_idea vulnerabilities (CVEs) · VulnSea