Executive brief
GoLand is JetBrains' integrated development environment for Go programming. The GoLand profiler includes an injected pprof server that lacked authentication controls, allowing unauthorized access to detailed application profiling data (CPU usage, memory allocation, goroutines, etc.). An attacker with network access to the profiling server could extract sensitive performance characteristics and internal application behavior without credentials.
Technical details
This vulnerability is an authentication bypass in GoLand's profiler component. The pprof (Go profiling) server injected by the profiler fails to enforce authentication, exposing profiling endpoints to unauthenticated network clients. The attack vector is network-based, requiring only network reachability to the profiler's listening port; no user interaction or prior authentication is needed. An attacker can retrieve CPU profiles, memory dumps, goroutine stacks, and other runtime metrics, potentially revealing application logic, data structures, and system resource usage patterns. The issue has been resolved in GoLand 2026.2.2.1 and later versions by adding authentication controls to the pprof server.
Affected products
- JetBrains GoLand before 2026.2.2.1
Timeline
- 2026-09-07: disclosed