Pycharm JetBrains Pycharm

Do you want an email whenever new security vulnerabilities are reported in JetBrains Pycharm?

By the Year

In 2024 there have been 0 vulnerabilities in JetBrains Pycharm . Pycharm did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 3 7.00
2021 1 7.80
2020 0 0.00
2019 1 7.50
2018 0 0.00

It may take a day or so for new Pycharm vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Pycharm Security Vulnerabilities

In JetBrains Rider before 2022.1 local code execution

CVE-2022-29821 7.7 - High - April 28, 2022

In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

Code Injection

In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

CVE-2022-29820 3.5 - Low - April 28, 2022

In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

Exposure of Resource to Wrong Sphere

JetBrains IntelliJ IDEA 2021.3.1 Preview

CVE-2021-45977 9.8 - Critical - February 25, 2022

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

In JetBrains PyCharm before 2020.3.4, local code execution was possible

CVE-2021-30005 7.8 - High - May 11, 2021

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

Insufficient Verification of Data Authenticity

JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes

CVE-2019-14958 7.5 - High - October 02, 2019

JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.

Allocation of Resources Without Limits or Throttling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for JetBrains Pycharm or by JetBrains? Click the Watch button to subscribe.

JetBrains
Vendor

subscribe