Impact
A malicious RSS feed can cause Glean to request arbitrary URLs without validation, capturing the entire response and storing it in an entry accessible to anyone who can retrieve that entry. This non‑blind SSRF allows attackers to probe internal networks, exfiltrate sensitive configuration, expose web services, and potentially retrieve cloud metadata tokens.
Affected Systems
Any deployment of Glean prior to version 0.2.6 is affected. The issue exists in the POST /api/feeds/discover endpoint that processes feed URLs and enqueues background fetch tasks, and is fixed in Glean 0.2.6 and later.
Risk and Exploitability
With a CVSS score of 7.7 and an EPSS score below 1%, the vulnerability is considered high severity but currently unlikely to be widely exploited. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw remotely by submitting a crafted RSS feed via the discovery API, causing the server to fetch and disclose the full response of the target URL through the entries API, thereby bypassing network perimeters and exposing internal resources.
OpenCVE Enrichment