CVE-2026-71205
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt).
- Affected products
- Changedetection.Io
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.2% (11th percentile)
- Weakness
- CWE-307
- NVD status
- Deferred
- Published
- 2026-08-05
CVE-2026-71205 at NVD
1 known exploit for CVE-2026-71205
Proof-of-concept code and exploit modules indexed by Sploitus