VYPR

Miniflux

by Miniflux Project

Source repositories

CVEs (4)

  • CVE-2023-27591HigMar 17, 2023
    risk 0.42cvss 7.5epss 0.01

    Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the…

  • CVE-2026-21885MedJan 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for…

  • CVE-2025-67713MedDec 11, 2025
    risk 0.33cvss 6.1epss 0.00

    Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like //ikotaslabs.com have an empty scheme and pass that check, allowing post-login…

  • CVE-2023-27592MedMar 17, 2023
    risk 0.24cvss 4.8epss 0.01

    Miniflux is a feed reader. Since v2.0.25, Miniflux will automatically proxy images served over HTTP to prevent mixed content errors. When an outbound request made by the Go HTTP client fails, the `html.ServerError` is returned unescaped without the expected Content Security…