XML External Entity Injection Vulnerability in YaCy Search Server
CVE-2026-82880

8.7HIGH

Key Information:

Vendor

Yacy

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82880?

YaCy Search Server versions up to 1.941 are susceptible to an XML external entity injection flaw present in SVG, FreeMind, and OpenSearch parsers. This vulnerability occurs because the parsers do not adequately disable external entity resolution. Consequently, an attacker can craft malicious documents that include DOCTYPE declarations with SYSTEM entities, which reference local files. When processed by the vulnerable server, these malicious documents facilitate the exfiltration of sensitive file contents into the indexed search results, potentially compromising the security and integrity of the stored data.

Affected Version(s)

yacy_search_server 0 <= 1.941

yacy_search_server 3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Sun
.