CVE-2026-71203: Dgtlmoon Changedetection.io
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request.
Affected products
- Dgtlmoon Changedetection.io: version 0.55.7 only
Published 2026-08-05. Last modified 2026-08-28.