CVE-2026-55185
Miniflux 2: Open Redirect Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization converts them to forward slashes. An unauthenticated attacker can provide such a redirect_url value to the login flow, bypass the relative-path and host checks, and redirect a victim to an attacker-controlled external site. This issue is fixed in version 2.3.1.
| CWE | CWE-601 |
| Vendor | miniflux |
| Product | v2 |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for miniflux v2
Be the first to know when new unknown vulnerabilities affecting miniflux v2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
miniflux / v2
< 2.3.1