Dgtlmoon · Changedetection.Io · CVE-2026-95270
**Name of the Vulnerable Software and Affected Versions**
dgtlmoon changedetection.io versions prior to 0.60.8
**Description**
A flaw in the Hash Comparison component allows for a remote attack. The `check password()` function within the `changedetectionio/flask app.py` file is susceptible to manipulation of the `Password` argument, which results in an observable timing discrepancy. A timing discrepancy occurs when the time taken to execute a function varies based on the input provided, potentially allowing an attacker to deduce secret information by measuring these differences.
**Recommendations**
Update dgtlmoon changedetection.io to version 0.60.8 or later.
As a temporary workaround, restrict access to the `check password()` function to minimize the risk of exploitation.