JetBrains JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any JetBrains product.

RSS Feeds for JetBrains security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by JetBrains Sorted by Most Security Vulnerabilities since 2018

JetBrains Teamcity271 vulnerabilities

JetBrains Youtrack151 vulnerabilities

JetBrains Intellij Idea82 vulnerabilities

JetBrains Hub37 vulnerabilities

JetBrains Ktor22 vulnerabilities

JetBrains Pycharm11 vulnerabilities

JetBrains Toolbox10 vulnerabilities

JetBrains Goland9 vulnerabilities

JetBrains Webstorm9 vulnerabilities

JetBrains Rider7 vulnerabilities

JetBrains Kotlin7 vulnerabilities

JetBrains Phpstorm6 vulnerabilities

JetBrains Rubymine4 vulnerabilities

JetBrains Resharper2 vulnerabilities

JetBrains Clion2 vulnerabilities

JetBrains Mps2 vulnerabilities

JetBrains Junie1 vulnerability

JetBrains Rustrover1 vulnerability

JetBrains Dataspell1 vulnerability

JetBrains Datagrip1 vulnerability

JetBrains Aqua1 vulnerability

Known Exploited JetBrains Vulnerabilities

The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-63077
August 5, 2026
JetBrains TeamCity Relative Path Traversal Vulnerability JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2024-27199 Exploit Probability: 100.0%
April 20, 2026
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
CVE-2024-27198 Exploit Probability: 99.9%
March 7, 2024
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-42793 Exploit Probability: 100.0%
October 4, 2023

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 116 vulnerabilities in JetBrains with an average score of 6.6 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.54.




Year Vulnerabilities Average Score
2026 116 6.61
2025 84 6.07
2024 103 6.20
2023 54 6.54
2022 75 6.48
2021 88 6.66
2020 57 6.38
2019 57 8.28
2018 2 0.00

It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-86506 Sep 07, 2026
GoLand Pprof Profiler Auth Bypass before 2026.2.2.1 In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
Goland
CVE-2026-86505 Sep 07, 2026
IntelliJ IDEA <2026.2.2: project metadata leak due to missing trust check In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
Intellij Idea
CVE-2026-86504 Sep 07, 2026
IntelliJ IDEA <2026.2.2 Dev Container RCE missing project-trust confirmation In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
Intellij Idea
CVE-2026-86503 Sep 07, 2026
IntelliJ IDEA <2026.2.2 SSRF via Kubernetes spec-source URL fetching In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching
Intellij Idea
CVE-2026-86502 Sep 07, 2026
IntelliJ IDEA <2026.2.2 gRPC TLS/Auth Bypass LCE In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
Intellij Idea
CVE-2026-86501 Sep 07, 2026
IntelliJ IDEA <2026.2.2 Terminal Cmd Log Injection In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
Intellij Idea
CVE-2026-86500 Sep 07, 2026
JetBrains YouTrack <2026.1.14047: Escalation Check Bypass Grants Admin In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
Youtrack
CVE-2026-86499 Sep 07, 2026
YouTrack pre-2026.1.14047: Predefined search fields leak group names In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
Youtrack
CVE-2026-86498 Sep 07, 2026
YouTrack <2025.3.160480: Unauthorized PUT on Link Sub-Resources In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
Youtrack
CVE-2026-86497 Sep 07, 2026
YouTrack <=2026.2.18769 Credential Exfiltration via Mailbox Host Change In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Youtrack
CVE-2026-86496 Sep 07, 2026
JetBrains YouTrack <2026.2.18769: Helpdesk Reporter Email Exposure In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
Youtrack
CVE-2026-86495 Sep 07, 2026
JetBrains YouTrack < 2026.2.18687 Missing Permission Checks for KB Articles In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
Youtrack
CVE-2026-86494 Sep 07, 2026
YouTrack <2026.2.18634: Whiteboard clone allows unauthorized link changes In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
Youtrack
CVE-2026-86493 Sep 07, 2026
YouTrack < 2026.2.18634 Checks Let Read-Only Users Modify Whiteboard Cards In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
Youtrack
CVE-2026-86492 Sep 07, 2026
YouTrack < 2026.2.18634 Cross-Tenant GitHub App Token Theft via Shared Cache In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
Youtrack
CVE-2026-86491 Sep 07, 2026
YouTrack XSS via Project/Org Icon Uploads (pre2026.2.18634) In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
Youtrack
CVE-2026-86490 Sep 07, 2026
YouTrack <2026.2.18634 Improper Permission Checks Overwrite Bundled Apps In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
Youtrack
CVE-2026-86489 Sep 07, 2026
JetBrains YouTrack IDOR in User Profile API before 2026.2.18634 In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
Youtrack
CVE-2026-86488 Sep 07, 2026
JetBrains YouTrack <2026.2.18634 iDOR via watchRules & issueListConfig In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
Youtrack
CVE-2026-86487 Sep 07, 2026
YouTrack WebSocket Canvas Injection before 2026.2.18634 In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
Youtrack
CVE-2026-86486 Sep 07, 2026
YouTrack VCS Webhook Handler Allows Open Access with Blank Secret <2026.2.18634 In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
Youtrack
CVE-2026-86485 Sep 07, 2026
JetBrains YouTrack <2026.2.18634: IP Spoofing via Headers Bitbucket Webhooks In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Youtrack
CVE-2026-86484 Sep 07, 2026
YouTrack <2026.2.18634 AngularJS Template Injection XSS In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
Youtrack
CVE-2026-86483 Sep 07, 2026
JetBrains YouTrack XSS via Agile Board Custom Field (< 2026.2.18634) In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
Youtrack
CVE-2026-86482 Sep 07, 2026
JetBrains YouTrack < 2026.2.18634 PrivEsc via Unchecked Group Membership In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
Youtrack
CVE-2026-86481 Sep 07, 2026
JetBrains YouTrack 2026.2.18634 Signed URL Reuse Disclosure In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
Youtrack
CVE-2026-86480 Sep 07, 2026
JetBrains Hub: Unauth Trusted Service Grants Superuser (pre-2026.2.52442) In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
Hub
CVE-2026-86479 Sep 07, 2026
JetBrains YouTrack 2026.2.18788 IDOR: Unauthorized REST API Access In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
Youtrack
CVE-2026-86478 Sep 07, 2026
YouTrack <2025.3.161254 & 2026.1.14042 Unauth Takeover In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
Youtrack
CVE-2026-75060 Aug 17, 2026
Unauthenticated code exec in JetBrains PyCharm <2026.2.1 via Jupyter MCP In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
Pycharm
CVE-2026-75059 Aug 17, 2026
JetBrains PyCharm Code Execution via Quick Documentation (Before 2026.2.1) In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Pycharm
CVE-2026-75058 Aug 17, 2026
IntelliJ IDEA Pre2026.2.1 xXE via Eclipse Settings Importer In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Intellij Idea
CVE-2026-75057 Aug 17, 2026
IntelliJ IDEA <2026.1.5 - Git Credentials Logged in Plaintext In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Intellij Idea
CVE-2026-75056 Aug 17, 2026
Remote Code Exec in IntelliJ IDEA <2026.2.1 via Markdown Export In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Intellij Idea
CVE-2026-75055 Aug 17, 2026
IntelliJ IDEA <2026.2.1, Hadoop ResourceManager XXE Local File Read In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
Intellij Idea
CVE-2026-75054 Aug 17, 2026
IntelliJ IDEA <2026.2.1 sSRF via OpenAPI preview proxy In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Intellij Idea
CVE-2026-75053 Aug 17, 2026
SRF in JetBrains IntelliJ IDEA < 2026.2.1 via DevKit Debug Listener In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
Intellij Idea
CVE-2026-75052 Aug 17, 2026
CVE-2026-75052: CMD exec via Markdown preview in IntelliJ IDEA < 2026.2.1 In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
Intellij Idea
CVE-2026-75050 Aug 17, 2026
YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950 In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
Youtrack
CVE-2026-75051 Aug 17, 2026
YouTrack 2026.2.17917: Unauthorized Project Transfer Between Orgs In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
Youtrack
CVE-2026-75049 Aug 17, 2026
YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950) In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
Youtrack
CVE-2026-75048 Aug 17, 2026
JetBrains YouTrack <2026.2.18068 XSS via Code Label In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Youtrack
CVE-2026-75047 Aug 17, 2026
JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177) In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Youtrack
CVE-2026-75046 Aug 17, 2026
YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046) In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
Youtrack
CVE-2026-75045 Aug 17, 2026
JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sig In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Youtrack
CVE-2026-68762 Aug 17, 2026
Ktor WebSocket Decompression DoS before 3.4.1 In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
Ktor
CVE-2026-75044 Aug 17, 2026
JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox Endpt In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Youtrack
CVE-2026-63077 Jul 27, 2026
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent Polling In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
CVE-2026-65907 Jul 23, 2026
TeamCity <2026.1.2 Git VCS CodeExec Vulnerability In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Teamcity
CVE-2026-65908 Jul 23, 2026
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious Python In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
Pycharm
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.