VYPR

stringer

by Stringer Rss

CVEs (1)

  • CVE-2026-55160HigSep 28, 2026
    risk 0.42cvss 7.6epss —

    Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services,…