YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82880.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-611"
]
}[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 296.0,
"function_hash": "253114117520710906708306885545795412856"
},
"id": "CVE-2026-82880-05e3bdb3",
"target": {
"function": "getParser",
"file": "source/net/yacy/document/parser/mmParser.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"269894528396889290421345609015362374073",
"63852848258733690195633855390551312856",
"197466823696600968901206104621033784542",
"329610203813327021758110752833970569693",
"274237720760827054830947659873154679851",
"242022797532493209716638083965128112006",
"22299921081814358682207236430113121386",
"220133595808515816858430264583907125017",
"236110901352793652058129087261641857551",
"83563450838181707931386806257969500754",
"321660501725871082476785721227489543517",
"218165324020684230914066271139045705229",
"17715561314935330516065188604706131232",
"62475332307317057559205485155857836021",
"263270315049907440132877468465707824436"
],
"threshold": 0.9
},
"id": "CVE-2026-82880-186d2cff",
"target": {
"file": "source/net/yacy/document/parser/xml/opensearchdescriptionReader.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 296.0,
"function_hash": "253114117520710906708306885545795412856"
},
"id": "CVE-2026-82880-68e34e1f",
"target": {
"function": "getParser",
"file": "source/net/yacy/document/parser/xml/opensearchdescriptionReader.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 296.0,
"function_hash": "253114117520710906708306885545795412856"
},
"id": "CVE-2026-82880-71c06c7e",
"target": {
"function": "getParser",
"file": "source/net/yacy/document/parser/images/svgParser.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"334325006341034609252658010373122686125",
"210643252108695771797813159560717573461",
"197466823696600968901206104621033784542",
"329610203813327021758110752833970569693",
"274237720760827054830947659873154679851",
"242022797532493209716638083965128112006",
"22299921081814358682207236430113121386",
"220133595808515816858430264583907125017",
"236110901352793652058129087261641857551",
"83563450838181707931386806257969500754",
"321660501725871082476785721227489543517",
"218165324020684230914066271139045705229",
"17715561314935330516065188604706131232",
"60466921694717550025193741167906379648",
"4300665876233712408931547315213190618"
],
"threshold": 0.9
},
"id": "CVE-2026-82880-828664ac",
"target": {
"file": "source/net/yacy/document/parser/mmParser.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"120856314992910365580626304005466836586",
"183550965096600777239221451601797241721",
"197466823696600968901206104621033784542",
"329610203813327021758110752833970569693",
"274237720760827054830947659873154679851",
"242022797532493209716638083965128112006",
"22299921081814358682207236430113121386",
"220133595808515816858430264583907125017",
"236110901352793652058129087261641857551",
"83563450838181707931386806257969500754",
"321660501725871082476785721227489543517",
"218165324020684230914066271139045705229",
"17715561314935330516065188604706131232",
"60466921694717550025193741167906379648",
"4300665876233712408931547315213190618"
],
"threshold": 0.9
},
"id": "CVE-2026-82880-887f3fe5",
"target": {
"file": "source/net/yacy/document/parser/images/svgParser.java"
},
"source": "https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82880.json"
"2026-09-02T08:05:28Z"