CVE-2026-82880
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail
CVSS
7.5
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 31 ago 2026 · Última mod.: 31 ago 2026 · CWE-611
Sin historial EPSS suficiente todavía.
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.
- github.comhttps://github.com/yacy/yacy_search_server
- github.comhttps://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/images/svgParser.java#L72
- github.comhttps://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/mmParser.java#L66
- github.comhttps://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/xml/opensearchdescriptionReader.java#L119
- github.comhttps://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44
- github.comhttps://github.com/yacy/yacy_search_server/issues/818
- www.vulncheck.comhttps://www.vulncheck.com/advisories/yacy-search-server-through-1.941-xml-external-entity-injection-via-parsers
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-765724.7 MED26.1%
——8A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.11dCVE-2026-203207.5 ALT31.5%
——9A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.
This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.11dCVE-2026-672686.5 MED1.1%
——0Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.10dCVE-2026-704236.5 MED19.8%
——6Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.10dCVE-2026-750585.5 MED2.0%
——1In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers3dCVE-2026-750555.5 MED2.0%
——1In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE3d