Medium
CVE-2026-32745
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
Medium
CVE-2026-32229
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
Medium
CVE-2026-28195
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build confi…
Low
CVE-2026-28196
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
Medium
CVE-2026-28194
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
High
CVE-2026-25847
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible