PT-2026-95100 · Glean · Glean

·

CVE-2026-54339

·

Published

2026-09-17

·

Updated

2026-09-21

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Glean versions prior to 0.2.6
Description An issue exists where the application fails to perform network-level validation on URLs provided in RSS feeds. When a user submits a feed url via the 'POST /api/feeds/discover' endpoint, the system processes it through the discover feed(feed url) function and FeedService.create subscription(), eventually triggering the fetch feed task. This task utilizes fetch feed(feed.url) and parse feed(), which assign links to ParsedEntry.url. Subsequently, fetch and extract fulltext(parsed entry.url) is called without proper validation in backend/packages/rss/glean rss/extractor.py and backend/apps/worker/glean worker/tasks/feed fetcher.py. This allows a malicious feed to trigger a non-blind server-side request forgery (SSRF), enabling the server to request private, loopback, link-local, or cloud-metadata resources. The resulting response is stored in Entry.content and can be accessed via the 'GET /api/entries/{id}' endpoint, potentially exposing internal services, ports, configurations, or cloud metadata access tokens.
Recommendations Update to version 0.2.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54339
GHSA-78QF-Q8FG-JCPG

Affected Products

Glean