Vulnerabilities
Vulnerable Software
Security Vulnerabilities
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
CVSS Score
8.4
EPSS Score
0.001
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
CVSS Score
4.3
EPSS Score
0.002
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
CVSS Score
7.8
EPSS Score
0.001
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVSS Score
10.0
EPSS Score
0.004
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVSS Score
10.0
EPSS Score
0.004
Published
2026-07-23
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVSS Score
3.5
EPSS Score
0.004
Published
2026-07-23
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
CVSS Score
7.8
EPSS Score
0.001
Published
2026-07-23
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
CVSS Score
7.8
EPSS Score
0.001
Published
2026-07-23
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-07-23
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying its own path-traversal guard, an unauthenticated attacker can bypass any route-scoped middleware and read files inside the static root that live under the guarded URL prefix. The bypass does not allow access outside the configured static root by itself, it defeats route-guard filtering only. The issue is patched in @fastify/static 10.1.1.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-07-23


Contact Us

Shodan ® - All rights reserved