๐Ÿ” CVE Alert

CVE-2026-55185

UNKNOWN 0.0

Miniflux 2: Open Redirect Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization converts them to forward slashes. An unauthenticated attacker can provide such a redirect_url value to the login flow, bypass the relative-path and host checks, and redirect a victim to an attacker-controlled external site. This issue is fixed in version 2.3.1.

CWE CWE-601
Vendor miniflux
Product v2
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for miniflux v2

Be the first to know when new unknown vulnerabilities affecting miniflux v2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

miniflux / v2
< 2.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/miniflux/v2/security/advisories/GHSA-m999-j542-5w3r github.com: https://github.com/miniflux/v2/pull/4362 github.com: https://github.com/miniflux/v2/commit/c896bafdaa19c3f280b02b1059f84706495f1949 github.com: https://github.com/miniflux/v2/releases/tag/2.3.1