Unrestricted Server-Side Request Forgery Vulnerability in Stringer RSS Reader
CVE-2026-55160
7.6HIGH
What is CVE-2026-55160?
The Stringer RSS reader previously had an unrestricted Server-Side Request Forgery (SSRF) vulnerability that enabled authenticated users to send unsolicited HTTP/HTTPS requests from the Stringer server to various internal services, including localhost and cloud metadata endpoints. This vulnerability posed a risk particularly when self-service signup was enabled, allowing even low-privileged users to exploit the system for scanning internal services or potentially extracting sensitive IAM credentials from cloud providers. The issue has been addressed and patched in commit 75cb095.
Affected Version(s)
stringer < 75cb0955919a362ac49d23c8a14892d0f59ea1c4
