Description
Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscription(), and enqueues fetch_feed_task. The background path calls fetch_feed(feed.url) and parse_feed(), which assigns each RSS item link to ParsedEntry.url. The task then passes ParsedEntry.url to fetch_and_extract_fulltext(parsed_entry.url) without network-level validation in backend/packages/rss/glean_rss/extractor.py and backend/apps/worker/glean_worker/tasks/feed_fetcher.py. A malicious feed can therefore make the server request private, loopback, link-local, or cloud-metadata resources. The fetched response is stored in Entry.content and can be retrieved through GET /api/entries/{id}, producing non-blind server-side request forgery with full response disclosure. This can bypass network perimeters, probe internal services and ports, expose internal configuration or web content, and potentially disclose cloud metadata access tokens. This issue is fixed in version 0.2.6.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery with Full Response Disclosure
Action: Patch Immediately
AI Analysis

Impact

A malicious RSS feed can cause Glean to request arbitrary URLs without validation, capturing the entire response and storing it in an entry accessible to anyone who can retrieve that entry. This non‑blind SSRF allows attackers to probe internal networks, exfiltrate sensitive configuration, expose web services, and potentially retrieve cloud metadata tokens.

Affected Systems

Any deployment of Glean prior to version 0.2.6 is affected. The issue exists in the POST /api/feeds/discover endpoint that processes feed URLs and enqueues background fetch tasks, and is fixed in Glean 0.2.6 and later.

Risk and Exploitability

With a CVSS score of 7.7 and an EPSS score below 1%, the vulnerability is considered high severity but currently unlikely to be widely exploited. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw remotely by submitting a crafted RSS feed via the discovery API, causing the server to fetch and disclose the full response of the target URL through the entries API, thereby bypassing network perimeters and exposing internal resources.

Generated by OpenCVE AI on September 19, 2026 at 01:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Glean to version 0.2.6 or later
  • Restart all Glean services to ensure the worker code is updated
  • If immediate upgrade is not feasible, restrict access to the /api/feeds/discover endpoint to trusted users or temporarily disable the endpoint while monitoring for suspicious activity

Generated by OpenCVE AI on September 19, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Leslieleung
Leslieleung glean
Vendors & Products Leslieleung
Leslieleung glean

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscription(), and enqueues fetch_feed_task. The background path calls fetch_feed(feed.url) and parse_feed(), which assigns each RSS item link to ParsedEntry.url. The task then passes ParsedEntry.url to fetch_and_extract_fulltext(parsed_entry.url) without network-level validation in backend/packages/rss/glean_rss/extractor.py and backend/apps/worker/glean_worker/tasks/feed_fetcher.py. A malicious feed can therefore make the server request private, loopback, link-local, or cloud-metadata resources. The fetched response is stored in Entry.content and can be retrieved through GET /api/entries/{id}, producing non-blind server-side request forgery with full response disclosure. This can bypass network perimeters, probe internal services and ports, expose internal configuration or web content, and potentially disclose cloud metadata access tokens. This issue is fixed in version 0.2.6.
Title Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Leslieleung Glean
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:14:53.214Z

Reserved: 2026-06-12T19:23:22.316Z

Link: CVE-2026-54339

cve-icon Vulnrichment

Updated: 2026-09-21T21:14:47.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:15.123

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)