CVE-2026-71205
EUVD-2026-5320205.08.2026, 08:16
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.