JetBrains IntelliJ IDEA
cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*
- < 2026.1
A vulnerability allowing XML External Entity (XXE) processing has been identified in JetBrains IntelliJ IDEA versions prior to 2026.1. This issue arises in the UI Designer form parser, where improper handling of XML data can be exploited.
Exploitation of this vulnerability could lead to an XXE attack, where an attacker can manipulate XML input to access internal files or services, potentially causing a denial-of-service condition.
Users can update to JetBrains IntelliJ IDEA version 2026.1.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.