HIGH 8.7 NVD
CVE-2026-82880
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.
References
- https://github.com/yacy/yacy_search_server
- https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/par
- https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/par
- https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/par
- https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11521 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.