Unrestricted Server-Side Request Forgery Vulnerability in Stringer RSS Reader
CVE-2026-55160

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-55160?

The Stringer RSS reader previously had an unrestricted Server-Side Request Forgery (SSRF) vulnerability that enabled authenticated users to send unsolicited HTTP/HTTPS requests from the Stringer server to various internal services, including localhost and cloud metadata endpoints. This vulnerability posed a risk particularly when self-service signup was enabled, allowing even low-privileged users to exploit the system for scanning internal services or potentially extracting sensitive IAM credentials from cloud providers. The issue has been addressed and patched in commit 75cb095.

Affected Version(s)

stringer < 75cb0955919a362ac49d23c8a14892d0f59ea1c4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.