GoLand
JetBrains · 8 CVEs
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed pro…
Sep 7, 2026
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configure…
Jul 23, 2026
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules…
Jul 23, 2026
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Jul 23, 2026
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
Jun 19, 2026
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Mar 25, 2025
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: Intelli…
Jun 10, 2024
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1,…
Feb 25, 2022
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
Apr 22, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-86506 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | MEDIUM | 0.38% | Sep 7, 2026 |
| CVE-2026-64803 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | HIGH | 0.21% | Jul 23, 2026 |
| CVE-2026-64802 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | HIGH | 0.21% | Jul 23, 2026 |
| CVE-2026-64800 | In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default | MEDIUM | 0.85% | Jul 23, 2026 |
| CVE-2026-53915 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | HIGH | 0.45% | Jun 19, 2026 |
| CVE-2025-29932 | In JetBrains GoLand before 2025.1 an XXE during debugging was possible | MEDIUM | 0.18% | Mar 25, 2025 |
| CVE-2024-37051 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 202… | CRITICAL | 3.84% | Jun 10, 2024 |
| CVE-2021-45977 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 202… | CRITICAL | 1.08% | Feb 25, 2022 |
| CVE-2020-11685 | In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. | HIGH | 0.88% | Apr 22, 2020 |
Showing 1 to 8 of 8 CVEs