High severity8.2NVD Advisory· Published Sep 25, 2026
CVE-2026-100391
CVE-2026-100391
Description
MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=2.4.9
- Range: <=2.4.9
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.