<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:changedetection_io:changedetection_io:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3achangedetection_iochangedetection_io/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:58:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3achangedetection_iochangedetection_io/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in changedetection.io</title><link>https://feed.craftedsignal.io/briefs/2026-09-changedetection-ssrf/</link><pubDate>Wed, 16 Sep 2026 21:58:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-changedetection-ssrf/</guid><description>changedetection.io versions 0.60.6 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to access internal network resources.</description><content:encoded><![CDATA[<p>changedetection.io versions up to and including 0.60.6 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-92815. The flaw resides in the handling of the 'Goto URL' action within browser steps. By manipulating the 'optional_value' parameter, an unauthenticated attacker can force the application to make HTTP requests to arbitrary internal IP addresses or services that are otherwise unreachable from the public internet. This allows for the discovery of internal infrastructure, unauthorized access to internal web services, and potential data exfiltration of internal-only content. Defenders should identify instances of changedetection.io and restrict the service's ability to initiate connections to sensitive internal networks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated actors to bypass network perimeter controls to probe internal resources. This can lead to the exposure of sensitive internal service configurations, metadata, or data contained within an organization's private network segment that the changedetection.io instance has network visibility into.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all affected changedetection.io instances to a version later than 0.60.6. Implement network-level egress filtering to restrict the changedetection.io service container or host from reaching private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and sensitive management interfaces.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>ssrf</category></item></channel></rss>