Server-Side Request Forgery in JetBrains IntelliJ IDEA Affected by Debug Listener Endpoint
CVE-2026-75053

5.4MEDIUM

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75053?

In JetBrains IntelliJ IDEA versions prior to 2026.2.1, a server-side request forgery (SSRF) vulnerability was identified, which could be exploited through the DevKit debug listener endpoint. This issue may allow an attacker to send unauthorized requests from the server, potentially leading to unauthorized access to internal services or sensitive information. Users are advised to update to the latest version to mitigate this vulnerability.

Affected Version(s)

IntelliJ IDEA 0 < 2026.2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.