CVE-2026-39376·Python vulnerability
FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL — with no depth limit, no visited-URL deduplication, and no redirect count cap. An attacker-controlled server that returns an infinite chain of HTML meta-refresh responses causes unbounded recursion, exhausting the Python call stack and crashing the process. This vulnerability can also be chained with the companion SSRF issue to reach internal network targets after bypassing the initial URL check. This vulnerability is fixed in 0.5.10.
- Severity
- high
- Software
- Python
- Fixed in
- 0.5.10
- Published
- 2026-04-07
Affected versions
Until: 0.5.10
Fixed in: 0.5.10
How to fix this CVE
Upgrade FastFeedParser to version 0.5.10 or later to prevent denial-of-service attacks via recursive meta-refresh redirect loops. This fix implements redirect depth limits, visited-URL tracking, and redirect count caps to safely handle malicious feed sources. Organizations using Python-based RSS/Atom feed parsing should prioritize this update to prevent application crashes from untrusted feed URLs.
sudo dnf update python3-fastfeedparser || sudo pip3 install --upgrade fastfeedparser>=0.5.10Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST/GET requests to feed parsing endpoints followed by HTTP 200 responses containing <meta http-equiv="refresh" content="0;url=..."> tags with recursive URL chains; application logs showing RecursionError or Python stack trace dumps during feed fetch operationsHow to check if you are affected
- Step 1: Check the installed FastFeedParser version by running: python3 -c "import fastfeedparser; print(fastfeedparser.__version__)"
- Step 2: Verify if your application uses FastFeedParser's parse() function on untrusted feed URLs by grepping source code: grep -r "fastfeedparser.parse" /path/to/app
- Step 3: Monitor system logs and Python exception logs for RecursionError or stack overflow messages that occur during feed parsing: grep -i "RecursionError\|stack overflow" /var/log/syslog /var/log/python*.log
- Step 4: After patching, confirm the upgrade: python3 -c "import fastfeedparser; print(fastfeedparser.__version__)" and verify version is >= 0.5.10
FAQ
What is CVE-2026-39376?
CVE-2026-39376 is a denial-of-service vulnerability in FastFeedParser that allows attackers to crash Python applications by serving malicious HTML pages with infinite meta-refresh redirect chains, causing unbounded recursion and stack exhaustion.
Is CVE-2026-39376 being actively exploited?
No, CVE-2026-39376 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available, though the vulnerability is straightforward to trigger.
What versions of FastFeedParser are affected by CVE-2026-39376?
All versions of FastFeedParser prior to 0.5.10 are vulnerable. The fix is included starting with version 0.5.10.
How do I check if my server is vulnerable to CVE-2026-39376?
Run: python3 -c "import fastfeedparser; print(fastfeedparser.__version__)" and confirm the version is 0.5.10 or higher. If the version is below 0.5.10 and your application parses untrusted feeds, you are vulnerable.
Does Defensia detect CVE-2026-39376?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If FastFeedParser or Python is installed on a monitored server, CVE-2026-39376 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-39376. Free for 1 server.
Get started free