PT-2026-2121 · Miniflux+1 · Miniflux+1

Eclipse07077-Ljw

·

Publicado

2026-01-07

·

Atualizado

2026-03-07

·

CVE-2026-21885

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Miniflux versions prior to 2.2.16
Description Miniflux is an open source feed reader. Prior to version 2.2.16, the media proxy endpoint, GET /proxy/{encodedDigest}/{encodedURL}, can be exploited to perform Server-Side Request Forgery (SSRF). An authenticated user can manipulate Miniflux to create a signed proxy URL for media URLs specified by the attacker within feed entry content. These URLs can include internal addresses, such as localhost, private RFC1918 ranges, or link-local metadata endpoints. Accessing the generated /proxy/... URL causes Miniflux to retrieve and return the response from the internal address.
Recommendations Upgrade to Miniflux version 2.2.16 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21885
GHSA-XWH2-742G-W3WP
GO-2026-4287
SUSE-SU-2026:0142-1

Produtos afetados

Debian
Miniflux