SSRF Vulnerability in Glean RSS Reader by Leslie Leung
CVE-2026-54339

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54339?

The Glean RSS reader, prior to version 0.2.6, contains a server-side request forgery vulnerability. This issue arises when user-supplied feed URLs are processed without proper validation, allowing attackers to make requests to private, loopback, or cloud-metadata resources. The flaw enables the server to inadvertently disclose sensitive information, such as internal configurations and access tokens, due to unchecked feed URL processing. The exploit can lead to severe data exposure risks, potentially breaching network perimeters. Users are encouraged to update to version 0.2.6 or later to mitigate this risk.

Affected Version(s)

glean < 0.2.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.