CVE Tools

Kotlin

8 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Kotlin, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Kotlin CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kotlin CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High450%
  • Medium450%

Latest CVEs

The 8 most recently published vulnerabilities affecting Kotlin.

  1. CVE-2026-53914In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata6.7
  2. CVE-2023-26154Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions ...5.9
  3. CVE-2022-24329In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.5.3
  4. CVE-2020-29582In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure perm...5.3
  5. CVE-2020-15824In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts c...8.8
  6. CVE-2019-10103JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This iss...8.1
  7. CVE-2019-10102JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attac...8.1
  8. CVE-2019-10101JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store