---
id: CVE-2026-55160
title: 'Stringer is a self-hosted, anti-social RSS reader'
summary: >-
  Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an
  unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any
  authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS
  requests…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-918
vendor: stringer-rss
product: stringer
affected:
  - stringer < 75cb0955919a362ac49d23c8a14892d0f59ea1c4
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T19:16:49.873'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55160'
references:
  - url: >-
      https://github.com/stringer-rss/stringer/commit/75cb0955919a362ac49d23c8a14892d0f59ea1c4
    label: security-advisories@github.com
  - url: 'https://github.com/stringer-rss/stringer/pull/1548'
    label: security-advisories@github.com
  - url: >-
      https://github.com/stringer-rss/stringer/security/advisories/GHSA-496x-437q-h35q
    label: security-advisories@github.com
  - url: >-
      https://github.com/stringer-rss/stringer/security/advisories/GHSA-496x-437q-h35q
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-28T18:33:57.068972Z'
ingestedAt: '2026-09-28T18:17:54.312Z'
---

## Overview

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup), even a low-privileged registered user can exploit this to scan internal services or steal cloud IAM credentials. This issue has been patched via commit 75cb095.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
