OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-55160

HIGH · CVSS 7.6 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users of the Stringer RSS reader to exploit an unrestricted Server-Side Request Forgery (SSRF) flaw, enabling them to send arbitrary HTTP/HTTPS requests to internal networks and cloud metadata endpoints. This could lead to unauthorized access to internal services and potential exposure of sensitive cloud IAM credentials, particularly when self-service signup is enabled. Organizations using Stringer should prioritize applying the patch from commit 75cb095 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55160
Severity
HIGH
CVSS
7.6
EPSS
0.28%

Original NVD Description

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup), even a low-privileged registered user can exploit this to scan internal services or steal cloud IAM credentials. This issue has been patched via commit 75cb095.