CVE-2026-71205: Dgtlmoon Changedetection.io
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt).
Affected products
- Dgtlmoon Changedetection.io: version 0.55.7 only
Published 2026-08-05. Last modified 2026-08-26.