CVE-2026-82880
YaCy Search Server XML external entity injection - the SVG, FreeMind and OpenSearch parsers resolve external entities
- Severity
- high
- Affected product
- YaCy
- Affected versions
- YaCy ≤ 1.941
- Fixed in
- YaCy 1.942
- Added to NewScan
- 2026-08-31
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints YaCy from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-31 (/daily-cve). YaCy through 1.941 leaves external entity resolution enabled in three document parsers, so a document the peer parses can read local files and make the peer issue requests - and a crawler is a machine whose whole job is parsing documents an attacker chose. `le` and not `lt` because the advisory's affected range is 'through 1.941' and 1.942 is the fix (patch 3c3a307e on yacy_search_server). VERSION-MATCH only: proving it in-band means getting a poisoned SVG/FreeMind/OpenSearch document into the peer's crawl, which is a write into someone else's index. The version arrives from the tech_signatures "YaCy" version_from added the same day (GET /Network.xml, anonymous on a stock install). NEGATIVE CASE MEASURED, positive case not: the only published image tag is `latest`, which is 1.942, and this row correctly stayed silent against it (techdb captured 1.942, no match) - there is no 1.941-or-earlier tag to boot, so the firing side of the gate was checked against the range logic rather than against a container. If an affected build ever becomes available, measure it rather than trusting this note.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →