VYPR
Medium severity4.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108735

CVE-2026-108735

Description

Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.