CVE-2026-55160: Stringer-Rss Stringer

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup), even a low-privileged registered user can exploit this to scan internal services or steal cloud IAM credentials. This issue has been patched via commit 75cb095.

Affected products

  • Stringer-Rss Stringer: before 75cb0955919a362ac49d23c8a14892d0f59ea1c4 (fixed in 75cb0955919a362ac49d23c8a14892d0f59ea1c4)

Published 2026-09-28. Last modified 2026-09-30.