{"id":"CVE-2026-82880","summary":"YaCy Search Server through 1.941 XML External Entity Injection via Parsers","details":"YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.","modified":"2026-09-02T08:05:28.969074Z","published":"2026-08-31T10:51:05.895Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82880.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82880.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82880"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/yacy-search-server-through-1.941-xml-external-entity-injection-via-parsers"},{"type":"REPORT","url":"https://github.com/yacy/yacy_search_server/issues/818"},{"type":"FIX","url":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44"},{"type":"PACKAGE","url":"https://github.com/yacy/yacy_search_server"},{"type":"ARTICLE","url":"https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/images/svgParser.java#L72"},{"type":"ARTICLE","url":"https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/mmParser.java#L66"},{"type":"ARTICLE","url":"https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/xml/opensearchdescriptionReader.java#L119"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yacy/yacy_search_server","events":[{"introduced":"0"},{"fixed":"f0464e7fbcfcb69127f0325910f92f113ce23677"},{"fixed":"3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.941"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["Release_1.941","Release_1.940","Release_1.930","Release_1.926","Release_1.925","Release_1.924","Release_1.922","Release_1.921","Release_1.92","Release_1.90","Release_1.82","Release_1.80","Release_1.72","Release_1.7","Release_1.68","0.99"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82880.json","vanir_signatures_modified":"2026-09-02T08:05:28Z","vanir_signatures":[{"digest":{"function_hash":"253114117520710906708306885545795412856","length":296},"id":"CVE-2026-82880-05e3bdb3","signature_type":"Function","signature_version":"v1","source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/mmParser.java","function":"getParser"},"deprecated":false},{"id":"CVE-2026-82880-186d2cff","signature_type":"Line","signature_version":"v1","source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/xml/opensearchdescriptionReader.java"},"deprecated":false,"digest":{"line_hashes":["269894528396889290421345609015362374073","63852848258733690195633855390551312856","197466823696600968901206104621033784542","329610203813327021758110752833970569693","274237720760827054830947659873154679851","242022797532493209716638083965128112006","22299921081814358682207236430113121386","220133595808515816858430264583907125017","236110901352793652058129087261641857551","83563450838181707931386806257969500754","321660501725871082476785721227489543517","218165324020684230914066271139045705229","17715561314935330516065188604706131232","62475332307317057559205485155857836021","263270315049907440132877468465707824436"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/xml/opensearchdescriptionReader.java","function":"getParser"},"deprecated":false,"digest":{"function_hash":"253114117520710906708306885545795412856","length":296},"id":"CVE-2026-82880-68e34e1f","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/images/svgParser.java","function":"getParser"},"deprecated":false,"digest":{"length":296,"function_hash":"253114117520710906708306885545795412856"},"id":"CVE-2026-82880-71c06c7e","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/mmParser.java"},"deprecated":false,"digest":{"line_hashes":["334325006341034609252658010373122686125","210643252108695771797813159560717573461","197466823696600968901206104621033784542","329610203813327021758110752833970569693","274237720760827054830947659873154679851","242022797532493209716638083965128112006","22299921081814358682207236430113121386","220133595808515816858430264583907125017","236110901352793652058129087261641857551","83563450838181707931386806257969500754","321660501725871082476785721227489543517","218165324020684230914066271139045705229","17715561314935330516065188604706131232","60466921694717550025193741167906379648","4300665876233712408931547315213190618"],"threshold":0.9},"id":"CVE-2026-82880-828664ac","signature_type":"Line"},{"source":"https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44","target":{"file":"source/net/yacy/document/parser/images/svgParser.java"},"deprecated":false,"digest":{"line_hashes":["120856314992910365580626304005466836586","183550965096600777239221451601797241721","197466823696600968901206104621033784542","329610203813327021758110752833970569693","274237720760827054830947659873154679851","242022797532493209716638083965128112006","22299921081814358682207236430113121386","220133595808515816858430264583907125017","236110901352793652058129087261641857551","83563450838181707931386806257969500754","321660501725871082476785721227489543517","218165324020684230914066271139045705229","17715561314935330516065188604706131232","60466921694717550025193741167906379648","4300665876233712408931547315213190618"],"threshold":0.9},"id":"CVE-2026-82880-887f3fe5","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}