CVE-2026-75054: SSRF
Published Aug 17, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2026.2.1
Event History
Aug 17, 2026
CVE Published
via NVD·04:17 PM
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75054?
CVE-2026-75054 has a severity score of medium, rated at 6.3 according to the CVSS 3.1 metrics.
2
How do I fix CVE-2026-75054?
To mitigate CVE-2026-75054, users should upgrade JetBrains IntelliJ IDEA to version 2026.2.1 or later.
3
What type of vulnerability is CVE-2026-75054?
CVE-2026-75054 is identified as a Server Side Request Forgery (SSRF) vulnerability.
4
What impact does CVE-2026-75054 have on untrusted projects?
CVE-2026-75054 allows SSRF attacks through the OpenAPI preview proxy when used in untrusted projects.
5
When was CVE-2026-75054 published?
CVE-2026-75054 was published on August 17, 2026.