Executive brief
FastFeedParser is a high-performance library used to process RSS and Atom news feeds. A vulnerability in how it handles web page redirects allows an attacker to provide a malicious link that triggers an infinite loop. This can cause the application to crash or become unresponsive, potentially disrupting services like news aggregators or feed readers for several hours.
Technical details
The `parse()` function in FastFeedParser prior to version 0.5.10 fails to implement a maximum redirect depth or URL deduplication when encountering HTML `<meta http-equiv="refresh">` tags. When a non-XML response is received, the parser extracts the refresh URL and recursively calls `parse()`, leading to unbounded recursion. An attacker can exploit this by hosting a server that returns infinite meta-refresh loops, exhausting the Python call stack (RecursionError) and potentially holding worker threads busy for hours due to per-request timeouts. Additionally, this can be used to bypass initial URL validation to perform Server-Side Request Forgery (SSRF) against internal network targets. The issue is fixed in version 0.5.10.
Affected products
- kagisearch fastfeedparser < 0.5.10
Timeline
- 2026-04-06: advisory: GitHub Security Advisory published by maintainers
- 2026-04-07: disclosed: CVE-2026-39376 published
- 2026-04-07: patched: Fixed in version 0.5.10