๐Ÿ” CVE Alert

CVE-2026-108735

MEDIUM 4.3

Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.

CWE CWE-918
Vendor miniflux
Product miniflux
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for miniflux miniflux

Be the first to know when new medium vulnerabilities affecting miniflux miniflux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

miniflux / miniflux
2.3.0 โ‰ค 2.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/miniflux-feed-proxy-url-private-network-bypass github.com: https://github.com/miniflux/v2/blob/c4d54f87a81b30aa173fddf05d7ff83ae7da5796/internal/reader/fetcher/request_builder.go#L155-L220 github.com: https://github.com/miniflux/v2/blob/c4d54f87a81b30aa173fddf05d7ff83ae7da5796/internal/urllib/url.go#L64-L72 github.com: https://github.com/miniflux/v2 vulncheck.com: https://www.vulncheck.com/advisories/miniflux-2.3.0-through-2.3.3-ssrf-via-per-feed-proxy-url

Credits

HaiND from the Post and Telecommunication Institute of Technology