Uncontrolled Recursion Affecting fastfeedparser package, versions [,0.5.10)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Uncontrolled Recursion vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-FASTFEEDPARSER-15954312
  • published9 Apr 2026
  • disclosed8 Apr 2026
  • creditredyank

Introduced: 8 Apr 2026

CVE-2026-39376  (opens in a new tab)
CWE-674  (opens in a new tab)

How to fix?

Upgrade fastfeedparser to version 0.5.10 or higher.

Overview

fastfeedparser is a High performance RSS, Atom, JSON and RDF feed parser in Python

Affected versions of this package are vulnerable to Uncontrolled Recursion through the parse function when processing HTML responses containing a <meta http-equiv="refresh"> tag, which leads to unbounded recursion without a redirect depth limit or visited-URL tracking. An attacker can exhaust system resources and cause a crash by supplying a URL that triggers an infinite chain of meta-refresh redirects.

CVSS Base Scores

version 4.0
version 3.1