CVE-2026-39376 is a denial of service vulnerability affecting FastFeedParser versions prior to 0.5.10, a widely-used RSS, Atom, and RDF parser. When the parse() function encounters a URL that returns an HTML page with a meta http-equiv="refresh" tag, it recursively follows the redirect with no depth limit, deduplication, or count restrictions, allowing attackers to trigger unbounded recursion and crash the application. Additionally, this vulnerability can be chained with a companion SSRF issue to potentially reach internal network targets. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector that requires no authentication or user interaction, making it easily exploitable across network boundaries. The impact is limited to availability, resulting in denial of service through stack exhaustion, though it poses no direct risk to confidentiality or integrity. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS probability score of 0.00052 indicates minimal exploitation likelihood relative to other published CVEs. Remediation is straightforward, as patches are available in version 0.5.10 and later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.10CPE matchmatch criteria | cpe:2.3:a:kagi:fastfeedparser:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.