CVE-CVE-2026-71205
Severity
MEDIUM
CVSS Score
6.5
Description
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt)....
PoCs for CVE-CVE-2026-71205
CVE-2026-71205-PoC
RCE
0
Nel-droid
2026-08-16