changedetection.io has an Authentication Bypass via Decorator Ordering
Published Apr 7, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.64%
Description
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerability is fixed in 0.54.8.
Affected products
-
- Version < 0.54.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dgtlmoon | Changedetection.io | n/a |
|
- < 0.54.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19675 Advisory
- https://github.com/advisories/GHSA-jmrh-xmgh-x9j4 Advisory
- https://github.com/dgtlmoon/changedetection.io/commit/31a760c2147e3e73a403baf6d7de34dc50429c85
- https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.8
- https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-jmrh-xmgh-x9j4 exploitx_refsource_CONFIRMMitigationVendor Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/changedetection-io/PYSEC-2026-28.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2026-35490
Change history (0)
No recorded changes yet.