Jetbrains
45 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-68762
MEDIUM 5.9
Ktor — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
2026-08-17
CVE-2026-75044
HIGH 8.1
Youtrack — In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an auth…
2026-08-17
CVE-2026-75045
CRITICAL 9.1
Youtrack — In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could dow…
2026-08-17
CVE-2026-75046
MEDIUM 4.3
Youtrack — In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search …
2026-08-17
CVE-2026-75047
MEDIUM 6.5
Youtrack — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpo…
2026-08-17
CVE-2026-75048
HIGH 8.2
Youtrack — In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
2026-08-17
CVE-2026-75049
MEDIUM 6.5
Youtrack — In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles …
2026-08-17
CVE-2026-75050
HIGH 7.1
Youtrack — In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters
2026-08-17
CVE-2026-75051
HIGH 8.1
Youtrack — In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
2026-08-17
CVE-2026-75052
LOW 3.6
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible…
2026-08-17
CVE-2026-75053
MEDIUM 5.4
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
2026-08-17
CVE-2026-75054
MEDIUM 6.3
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projec…
2026-08-17
CVE-2026-75055
MEDIUM 5.5
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
2026-08-17
CVE-2026-75056
HIGH 7.8
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
2026-08-17
CVE-2026-75057
MEDIUM 6.2
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
2026-08-17
CVE-2026-75058
MEDIUM 5.5
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
2026-08-17
CVE-2026-75059
MEDIUM 4.4
Pycharm — In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
2026-08-17
CVE-2026-75060
HIGH 8.4
Pycharm — In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
2026-08-17
CVE-2026-63077
CRITICAL 9.8
Teamcity — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the ag…● exploited
2026-07-27
CVE-2026-64800
LOW 3.5
Goland — In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
2026-07-23
CVE-2026-64802
HIGH 7.8
Goland — In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the G…
2026-07-23
CVE-2026-64803
HIGH 7.8
Goland — In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the …
2026-07-23
CVE-2026-64804
HIGH 8.4
Webstorm — In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via pr…
2026-07-23
CVE-2026-64805
HIGH 8.4
Webstorm — In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via pr…
2026-07-23
CVE-2026-64806
HIGH 8.4
Webstorm — In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via th…
2026-07-23
CVE-2026-64807
HIGH 7.8
Webstorm — In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter config…
2026-07-23
CVE-2026-64808
HIGH 8.4
Phpstorm — In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via pr…
2026-07-23
CVE-2026-64809
HIGH 8.4
Phpstorm — In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via th…
2026-07-23
CVE-2026-64810
MEDIUM 4.3
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent u…
2026-07-23
CVE-2026-64811
HIGH 7.8
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust v…
2026-07-23
CVE-2026-64812
CRITICAL 10
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development ses…
2026-07-23
CVE-2026-64813
CRITICAL 10
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Developme…
2026-07-23
CVE-2026-64814
HIGH 8.6
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
2026-07-23
CVE-2026-64815
HIGH 8.1
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
2026-07-23
CVE-2026-65906
HIGH 8.8
Teamcity — In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
CVE-2026-65907
CRITICAL 9.1
Teamcity — In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
2026-07-23
CVE-2026-65908
HIGH 8.6
Pycharm — In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was poss…
2026-07-23
CVE-2026-62422
CRITICAL 10
Youtrack — In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.…
2026-07-14
CVE-2026-59791
LOW 3.5
Youtrack — In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
2026-07-10
CVE-2026-59792
CRITICAL 9.6
Intellij Idea — In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID …
2026-07-10
CVE-2026-59793
HIGH 8.8
Teamcity — In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
2026-07-10
CVE-2026-59794
HIGH 7.3
Teamcity — In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported dat…
2026-07-10
CVE-2026-59795
HIGH 8.1
Teamcity — In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
2026-07-10
CVE-2026-59796
HIGH 8.1
Teamcity — In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
2026-07-10
CVE-2026-61492
LOW 3.5
Youtrack — In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
2026-07-10