XML External Entity Injection Vulnerability in YaCy Search Server
CVE-2026-82880
8.7HIGH
What is CVE-2026-82880?
YaCy Search Server versions up to 1.941 are susceptible to an XML external entity injection flaw present in SVG, FreeMind, and OpenSearch parsers. This vulnerability occurs because the parsers do not adequately disable external entity resolution. Consequently, an attacker can craft malicious documents that include DOCTYPE declarations with SYSTEM entities, which reference local files. When processed by the vulnerable server, these malicious documents facilitate the exfiltration of sensitive file contents into the indexed search results, potentially compromising the security and integrity of the stored data.
Affected Version(s)
yacy_search_server 0 <= 1.941
yacy_search_server 3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44
