CVE-2026-82880
YaCy Search Server through 1.941 XML External Entity Injection via Parsers
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.
| CWE | CWE-611 |
| Vendor | yacy |
| Product | yacy_search_server |
| Published | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for yacy yacy_search_server
Be the first to know when new high vulnerabilities affecting yacy yacy_search_server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
yacy / yacy_search_server
0 โค 1.941
References
github.com: https://github.com/yacy/yacy_search_server/issues/818 github.com: https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/images/svgParser.java#L72 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/mmParser.java#L66 github.com: https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/xml/opensearchdescriptionReader.java#L119 github.com: https://github.com/yacy/yacy_search_server vulncheck.com: https://www.vulncheck.com/advisories/yacy-search-server-through-1.941-xml-external-entity-injection-via-parsers
Credits
Yu Sun