<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:53:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319282</link>
      <description>EUVD-2026-319282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319282</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41895</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41895</link>
      <description>&lt;p&gt;changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41895</guid>
    </item>
    <item>
      <title>GHSA-v7cp-2cx9-x793 — changedetection.io project has an XXE vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v7cp-2cx9-x793</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: changedetection.io&lt;/p&gt;
&lt;p&gt;# changedetection.io_XXE_01 Vulnerability Report: We discovered a XXE vulnerability in the changedetection.io project&lt;/p&gt;
&lt;p&gt;While analyzing the code logic, it was determined that an area may lead to unintended behavior under specific conditions. With the project&amp;#39;s security in mind, see the analysis results to discern whether this may indicate a potential security risk.&lt;/p&gt;
&lt;p&gt;## Overview
- SOURCE_VERSION: `0.54.9 (9f3a9fdc18bba404244801e5df8109e213ce9ff4)`
- Vulnerability type: `XXE`
- Finding title: `XML XPath helpers parse untrusted XML with entity resolution left to lxml defaults`
- Affected location: `changedetectionio/html_tools.py:287`&lt;/p&gt;
&lt;p&gt;## Root Cause
`xpath_filter()` switches to XML mode for XML/RSS content and creates `etree.XMLParser(strip_cdata=False)` without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with `etree.fromstring(...)`.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink Chain
1. Untrusted XML/RSS response content is fetched from monitored URLs.
2. Stream detection marks the content as XML/RSS and the include-filter path invokes `xpath_filter(..., is_xml=True)`.
3. `xpath_filter()` builds the default XML parser and calls `etree.fromstring(...)` at `changedetectionio/html_tools.py:287`.
4. External entity declarations in attacker XML can be expanded by parser-default behavior in affected runtime combinations.&lt;/p&gt;
&lt;p&gt;## Exploitation Preconditions
1. Attacker controls the watched XML/RSS respons…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: changedetection.io&lt;/p&gt;
&lt;p&gt;# changedetection.io_XXE_01 Vulnerability Report: We discovered a XXE vulnerability in the changedetection.io project&lt;/p&gt;
&lt;p&gt;While analyzing the code logic, it was determined that an area may lead to unintended behavior under specific conditions. With the project&amp;#39;s security in mind, see the analysis results to discern whether this may indicate a potential security risk.&lt;/p&gt;
&lt;p&gt;## Overview
- SOURCE_VERSION: `0.54.9 (9f3a9fdc18bba404244801e5df8109e213ce9ff4)`
- Vulnerability type: `XXE`
- Finding title: `XML XPath helpers parse untrusted XML with entity resolution left to lxml defaults`
- Affected location: `changedetectionio/html_tools.py:287`&lt;/p&gt;
&lt;p&gt;## Root Cause
`xpath_filter()` switches to XML mode for XML/RSS content and creates `etree.XMLParser(strip_cdata=False)` without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with `etree.fromstring(...)`.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink Chain
1. Untrusted XML/RSS response content is fetched from monitored URLs.
2. Stream detection marks the content as XML/RSS and the include-filter path invokes `xpath_filter(..., is_xml=True)`.
3. `xpath_filter()` builds the default XML parser and calls `etree.fromstring(...)` at `changedetectionio/html_tools.py:287`.
4. External entity declarations in attacker XML can be expanded by parser-default behavior in affected runtime combinations.&lt;/p&gt;
&lt;p&gt;## Exploitation Preconditions
1. Attacker controls the watched XML/RSS respons…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v7cp-2cx9-x793</guid>
    </item>
    <item>
      <title>PYSEC-2026-29</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-29</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: changedetection-io&lt;/p&gt;
&lt;p&gt;changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: changedetection-io&lt;/p&gt;
&lt;p&gt;changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-29</guid>
    </item>
  </channel>
</rss>
