CVE Tools

Intellij Idea

81 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Intellij Idea, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Intellij Idea CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Intellij Idea CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-084
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-041
2026-054
2026-060
2026-077
2026-087
2026-095

Severity

How the 81 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1012%
  • High2227%
  • Medium3341%
  • Low1620%

Latest CVEs

The 15 most recently published vulnerabilities affecting Intellij Idea.

  1. CVE-2026-86505In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace3.3
  2. CVE-2026-86503In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching3.3
  3. CVE-2026-86504In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution7.8
  4. CVE-2026-86501In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log2.8
  5. CVE-2026-86502In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts8.4
  6. CVE-2026-75057In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log6.2
  7. CVE-2026-75058In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers5.5
  8. CVE-2026-75056In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible7.8
  9. CVE-2026-75055In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE5.5
  10. CVE-2026-75054In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects6.3
  11. CVE-2026-75053In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint5.4
  12. CVE-2026-75052In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects3.6
  13. CVE-2026-64814In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session8.6
  14. CVE-2026-64815In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files8.1
  15. CVE-2026-64813In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session10.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store