PT-2025-53608 · Freshrss · Freshrss

Inverle

·

Published

2025-12-26

·

Updated

2025-12-31

·

CVE-2025-68148

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreshRSS versions 1.27.0 through 1.27.9
Description An attacker could disrupt access to RSS feeds for all users of an instance by manipulating the proxy settings to send a large number of 429 Retry-After requests. This denial of service makes the application unusable for most users.
Recommendations Update to version 1.28.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-68148
GHSA-QW34-FRG7-GF78

Affected Products

Freshrss