Security Advisory

CVE-2026-71203

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 06:58:56
Last updated 2026-08-05 13:21:15
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key.