CVE-2026-55160 Details
Description
Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup), even a low-privileged registered user can exploit this to scan internal services or steal cloud IAM credentials. This issue has been patched via commit 75cb095.
A server-side request forgery (SSRF) vulnerability has been identified in Stringer, a self-hosted RSS reader, affecting all versions prior to the patch in commit 75cb095. This vulnerability allows authenticated users to manipulate the server into sending arbitrary HTTP or HTTPS requests to internal networks, localhost services, and cloud metadata endpoints, such as AWS IMDS. In deployments with self-service signup enabled, even low-privileged users can exploit this vulnerability to scan internal services or access cloud IAM credentials.
Users can update to the patched version of Stringer, available in commit 75cb095, which includes a 'SafeFetch' helper to guard against SSRF by restricting URL schemes and validating connections to public IPs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/stringer-rss/stringer/security/advisories/GHSA-496x-437q-h35q | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/stringer-rss/stringer/commit/75cb0955919a362ac49d23c8a14892d0f59ea1c4 | [email protected] | Source CodeVendor |
| https://github.com/stringer-rss/stringer/pull/1548 | [email protected] | Issue TrackingVendor |
| https://github.com/stringer-rss/stringer/security/advisories/GHSA-496x-437q-h35q | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Stringer | < 2026-06-10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion