Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-27696— changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs

Quick assessment

Affected
dgtlmoon changedetection.io
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

changedetection.io是dgtlmoon个人开发者的一个网站变更检测、监控和通知应用程序。 changedetection.io 0.54.1之前版本存在安全漏洞,该漏洞源于URL验证函数is_safe_valid_url()未针对私有、环回或链路本地地址范围验证监视URL的解析IP地址,可能导致经过身份验证的用户(或在未配置密码的默认情况下任何用户)添加对内部网络URL的监视,从而引发服务端请求伪造,导致内部服务数据泄露。

CVSS 8.6 · High EPSS 0.48% · P39
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-27696

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs
Source: CVE Program / CVE List V5
Vulnerability Description
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function `is_safe_valid_url()` does not validate the resolved IP address of watch URLs against private, loopback, or link-local address ranges. An authenticated user (or any user when no password is configured, which is the default) can add a watch for internal network URLs. The application fetches these URLs server-side, stores the response content, and makes it viewable through the web UI — enabling full data exfiltration from internal services. Version 0.54.1 contains a fix for the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
changedetection.io 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
changedetection.io是dgtlmoon个人开发者的一个网站变更检测、监控和通知应用程序。 changedetection.io 0.54.1之前版本存在安全漏洞,该漏洞源于URL验证函数is_safe_valid_url()未针对私有、环回或链路本地地址范围验证监视URL的解析IP地址,可能导致经过身份验证的用户(或在未配置密码的默认情况下任何用户)添加对内部网络URL的监视,从而引发服务端请求伪造,导致内部服务数据泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
dgtlmoon changedetection.io < 0.54.1 -

II. Public POCs for CVE-2026-27696

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-27696

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-27696 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-27696

No comments yet


Leave a comment