CVE-2026-55160
Received Received - Intake

Unrestricted SSRF in Stringer RSS Reader

Vulnerability report for CVE-2026-55160, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup), even a low-privileged registered user can exploit this to scan internal services or steal cloud IAM credentials. This issue has been patched via commit 75cb095.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stringer_rss stringer to 75cb0955 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55160 is a Server-Side Request Forgery (SSRF) vulnerability in the Stringer RSS reader. It allows authenticated users to manipulate feed URLs to force the server to send HTTP/HTTPS requests to internal networks, localhost services, or cloud metadata endpoints like AWS IMDS. The issue occurs because the application does not validate user-supplied URLs or their destinations, including following redirects without checks.

Detection Guidance

To detect this SSRF vulnerability, monitor network traffic for unusual outbound requests from the Stringer server, especially to localhost, private IP ranges, or cloud metadata endpoints like 169.254.169.254. Check server logs for feed URL fetches with non-HTTP(S) schemes or redirects to internal addresses.

Impact Analysis

This vulnerability can allow attackers to scan internal services, steal cloud IAM credentials, or access sensitive internal resources. If self-service signup is enabled, even low-privileged users can exploit it. The CVSS score of 7.6 indicates high severity with low attack complexity and no user interaction required.

Compliance Impact

This SSRF vulnerability could lead to unauthorized access to internal systems or cloud metadata endpoints, potentially exposing sensitive data such as user credentials or configuration details. Such breaches may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if exploited in healthcare environments.

Mitigation Strategies

Immediately update Stringer to commit 75cb095 or later. Disable self-service user signup if enabled. Restrict network access to the Stringer server to prevent unauthorized outbound requests. Review and audit all feed URLs and server logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55160. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart