Executive brief
JetBrains IntelliJ IDEA is a widely-used integrated development environment (IDE) for Java and other languages. A server-side request forgery (SSRF) vulnerability in the DevKit debug listener component allowed attackers to make unauthorized requests to internal network resources or external services, potentially leading to information disclosure or lateral movement within a development environment.
Technical details
A server-side request forgery (SSRF) vulnerability existed in the DevKit debug listener endpoint of JetBrains IntelliJ IDEA versions prior to 2026.2.1. The vulnerability allowed an attacker with network access to the IDE's debug listener to craft malicious requests that would be processed by the IDE, resulting in unwanted HTTP requests to arbitrary targets. This could be exploited to access internal services, retrieve sensitive data, or pivot within a network. The vulnerability was patched in version 2026.2.1.
Affected products
- JetBrains IntelliJ IDEA before 2026.2.1
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: Fixed in version 2026.2.1