Goland JetBrains Goland

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in JetBrains Goland.

By the Year

In 2026 there have been 1 vulnerability in JetBrains Goland with an average score of 7.1 out of ten. Last year, in 2025 Goland had 1 security vulnerability published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Goland in 2026 could surpass last years number.




Year Vulnerabilities Average Score
2026 1 7.10
2025 1 0.00
2024 1 7.50
2023 0 0.00
2022 1 9.80
2021 0 0.00
2020 1 0.00

It may take a day or so for new Goland vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Goland Security Vulnerabilities

GoLand RCE via Untrusted Assigner in Project Config before 2026.1.3 (JetBrains)
CVE-2026-53915 7.1 - High - June 19, 2026

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

External Control of File Name or Path

GoLand XXE During Debugging Before 2025.1
CVE-2025-29932 - March 25, 2025

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

XXE

JetBrains IDEs <=2024.2 Token Exposure via 3rd-Party Sites (CVE-2024-37051)
CVE-2024-37051 7.5 - High - June 10, 2024

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

Insufficiently Protected Credentials

JetBrains IntelliJ IDEA 2021.3.1 Preview
CVE-2021-45977 9.8 - Critical - February 25, 2022

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed
CVE-2020-11685 - April 22, 2020

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for JetBrains Goland or by JetBrains? Click the Watch button to subscribe.

JetBrains
Vendor

subscribe