
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39376 is an uncontrolled recursion (CWE-674) vulnerability in FastFeedParser, a high-performance RSS, Atom, and RDF parser for Python developed by Kagi. Prior to version 0.5.10, the parse() function recursively follows HTML <meta http-equiv="refresh"> redirect chains without any depth limit, visited-URL deduplication, or redirect count cap, enabling a denial-of-service attack via stack exhaustion. All versions up to and including 0.5.9 are affected. The vulnerability was published on April 7, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat CVE).
The root cause is uncontrolled recursion (CWE-674 / CWE-400) in fastfeedparser/main.py. When parse() fetches a URL and the response fails XML parsing, it extracts a meta-refresh redirect URL via _extract_meta_refresh_url() — which resolves relative, protocol-relative, and absolute URLs using urljoin() — and then unconditionally calls parse(redirect_url, ...) with no guard against loops or depth limits. An attacker-controlled server returning an infinite chain of HTML meta-refresh responses triggers unbounded recursion: each recursive call allocates a Python stack frame, performs a real HTTP request (30-second timeout), and parses HTML, meaning Python's default recursion limit of 1,000 can take up to ~8 hours to exhaust, holding a server worker thread the entire time. Additionally, the vulnerability can be chained with a companion SSRF issue, as the first redirect response can point to an internal network address (e.g., http://192.168.1.1/) that bypasses application-level URL validation applied only to the initial URL (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to cause a denial of service by holding server worker threads indefinitely and ultimately crashing the worker process via a RecursionError after approximately 1,000 redirects. Any application that accepts user-supplied feed URLs and calls fastfeedparser.parse() is affected, including RSS aggregators, feed preview services, and "subscribe by URL" features. As a secondary impact, the redirect chain can be used to pivot SSRF requests to internal network targets (e.g., cloud metadata endpoints, internal APIs) that would otherwise be blocked by application-level URL validation, potentially exposing sensitive internal resources (GitHub Advisory).
Public proof-of-concept (PoC) code is available on GitHub, demonstrating the vulnerability via a self-contained Python script that monkeypatches _fetch_url_content to simulate an infinite meta-refresh chain and trigger the recursion crash locally without requiring an external server (PoC GitHub, GitHub Advisory). No authentication is required to exploit this vulnerability, and attack complexity is low. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.04%, and the vulnerability is not listed in the CISA KEV catalog (Red Hat CVE).
<meta http-equiv="refresh" content="0; url=http://attacker.com/next"> tag on every request, creating an infinite redirect chain. Optionally, after the first response, redirect to an internal target (e.g., http://169.254.169.254/latest/meta-data/) to chain with SSRF.http://attacker.com/loop) as a feed URL to the vulnerable application, triggering a call to fastfeedparser.parse().parse() function fetches the URL, fails XML parsing, extracts the meta-refresh redirect URL, and recursively calls itself — repeating indefinitely with no depth check, consuming stack frames and holding the worker thread.RecursionError crashes the worker process. With a 30-second HTTP timeout per call, a single attacker request can occupy a thread for up to ~8 hours before crashing (GitHub Advisory, PoC GitHub).http://attacker.com/step1/, /step2/, etc.); outbound connections to internal network addresses (e.g., 169.254.169.254, 192.168.x.x) originating from the feed parser process, indicating potential SSRF chaining.RecursionError tracebacks in application error logs referencing fastfeedparser/main.py and the parse() function.Upgrade FastFeedParser to version 0.5.10 or later, which introduces redirect depth limits, visited-URL deduplication, and a redirect count cap to prevent unbounded recursion (GitHub Advisory). If immediate patching is not possible, restrict FastFeedParser to only process URLs from a trusted allowlist and implement network-level egress controls to limit outbound connections from the application to known-safe hosts. Additionally, consider setting a lower Python recursion limit (sys.setrecursionlimit()) as a temporary mitigation, though this does not fully address the thread-blocking aspect of the vulnerability.
The vulnerability was credited to researcher redyank, who also published the PoC on GitHub (PoC GitHub). The advisory was published by the FastFeedParser maintainer vprelovac on April 6, 2026, and picked up by security aggregators including GitLab Advisories, VulDB, and The Hacker Wire shortly after disclosure (GitHub Advisory). Red Hat also tracked the CVE in their security database (Red Hat CVE). No significant broader community controversy or vendor dispute has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."