← All CVEs NewScan detects
high

CVE-2026-82880

YaCy Search Server XML external entity injection - the SVG, FreeMind and OpenSearch parsers resolve external entities

Severity
high
Affected product
YaCy
Affected versions
YaCy ≤ 1.941
Fixed in
YaCy 1.942
Added to NewScan
2026-08-31
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints YaCy from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-31 (/daily-cve). YaCy through 1.941 leaves external entity resolution enabled in three document parsers, so a document the peer parses can read local files and make the peer issue requests - and a crawler is a machine whose whole job is parsing documents an attacker chose. `le` and not `lt` because the advisory's affected range is 'through 1.941' and 1.942 is the fix (patch 3c3a307e on yacy_search_server). VERSION-MATCH only: proving it in-band means getting a poisoned SVG/FreeMind/OpenSearch document into the peer's crawl, which is a write into someone else's index. The version arrives from the tech_signatures "YaCy" version_from added the same day (GET /Network.xml, anonymous on a stock install). NEGATIVE CASE MEASURED, positive case not: the only published image tag is `latest`, which is 1.942, and this row correctly stayed silent against it (techdb captured 1.942, no match) - there is no 1.941-or-earlier tag to boot, so the firing side of the gate was checked against the range logic rather than against a container. If an affected build ever becomes available, measure it rather than trusting this note.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →