CVE-2026-71205: Dgtlmoon Changedetection.io

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt).

Affected products

  • Dgtlmoon Changedetection.io: version 0.55.7 only

Published 2026-08-05. Last modified 2026-08-26.