Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108735
CVE-2026-108735
Description
Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/miniflux/v2/blob/c4d54f87a81b30aa173fddf05d7ff83ae7da5796/internal/reader/fetcher/request_builder.gonvd
- github.com/miniflux/v2/blob/c4d54f87a81b30aa173fddf05d7ff83ae7da5796/internal/urllib/url.gonvd
- hackmd.io/@haind03/miniflux-feed-proxy-url-private-network-bypassnvd
- www.vulncheck.com/advisories/miniflux-2.3.0-through-2.3.3-ssrf-via-per-feed-proxy-urlnvd
News mentions
0No linked articles in our index yet.