Junglewise Threat Intelligence

CVE-2026-95271: dgtlmoon changedetection.io authentication timing attack

CVE-2026-95271 · Severity: high · CVSS 7.3 · Published 2026-09-22

Technologies: Dgtlmoon Changedetection.Io. Vendors: Dgtlmoon.

Executive brief

changedetection.io is a website monitoring tool that tracks changes to web pages. A timing attack vulnerability in its authentication mechanism allows remote attackers to bypass authentication or guess credentials by measuring response times, potentially gaining unauthorized access to sensitive monitoring data and configuration.

Technical details

A timing attack vulnerability exists in the check_authentication function in changedetectionio/flask_app.py due to improper authentication validation that leaks timing information. An attacker can exploit this via remote network access without authentication to discover valid credentials by analyzing response time differences, compromising the authentication hook component.

Affected products

  • dgtlmoon changedetection.io up to 0.60.7

Timeline

  • 2026-09-22: disclosed: Vulnerability disclosed publicly via GitHub; vendor did not respond
  • 2026-09-22: other: Exploit/proof-of-concept code made available

References

Related threats