CVE-2026-82880: YaCy Search Server through 1.941 XML External Entity Injection via Parsers

Published Aug 31, 2026
·
Updated

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.

Affected Software

1 affected component
YaCy YaCy Search Server<=1.941

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade YaCy Search Server to a version that resolves this vulnerability.

    Fixed in 1.941
  2. Configuration

    Update YaCy Search Server so that the SVG, FreeMind, and OpenSearch parsers disable external entity resolution to prevent XML External Entity (XXE) injection from resolving SYSTEM entities to local files.

    YaCy Search Server (SVG, FreeMind, OpenSearch parsers) external entity resolution (XML External Entity, XXE) = disabled

Event History

Aug 31, 2026
CVE Published
via MITRE·10:51 AM
Data Sourced
via MITRE·10:51 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What content paths expose a YaCy deployment to this issue?

The affected parsers handle SVG, FreeMind, and OpenSearch documents. A deployment is exposed when its crawler processes attacker-published documents of these types containing a DOCTYPE declaration with a SYSTEM entity.

2

What does an attacker need to exploit the vulnerability?

The attacker needs to publish a malicious SVG, FreeMind, or OpenSearch document that the YaCy crawler will parse. No authentication or user interaction is required according to the supplied CVSS vector.

3

What is the likely impact if exploitation succeeds?

The parser can resolve a SYSTEM entity that points to a local file, and the crawler can place that file's contents into the searchable index. This creates a high confidentiality impact; integrity and availability impacts are not indicated.

4

How can I check whether my instance may already have been affected?

Review indexed content for unexpected local-file data associated with crawled SVG, FreeMind, or OpenSearch documents, especially documents containing DOCTYPE declarations and SYSTEM entities. The provided information does not identify specific file paths or detection signatures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203