{"id":"CVE-2026-41895","aliases":["GHSA-v7cp-2cx9-x793","PYSEC-2026-29"],"url":"https://o3.security/vulnerability/CVE-2026-41895","summary":"changedetection.io: XXE vulnerability in the changedetection.io project","details":"changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...).","published":"2026-05-12T16:52:23.680Z","modified":"2026-07-15T01:49:00.195659351Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"changedetection-io","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41895.json"},{"type":"ADVISORY","url":"https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-v7cp-2cx9-x793"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41895"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:00.195659351Z"}}