๐Ÿ” CVE Alert

CVE-2026-82880

HIGH 7.5

YaCy Search Server through 1.941 XML External Entity Injection via Parsers

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.

CWE CWE-611
Vendor yacy
Product yacy_search_server
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for yacy yacy_search_server

Be the first to know when new high vulnerabilities affecting yacy yacy_search_server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

yacy / yacy_search_server
0 โ‰ค 1.941

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/yacy/yacy_search_server/issues/818 github.com: https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/images/svgParser.java#L72 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/mmParser.java#L66 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/xml/opensearchdescriptionReader.java#L119 github.com: https://github.com/yacy/yacy_search_server vulncheck.com: https://www.vulncheck.com/advisories/yacy-search-server-through-1.941-xml-external-entity-injection-via-parsers

Credits

Yu Sun