Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.

Project Subscriptions

Vendors Products
Miniflux Project Subscribe
Miniflux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
Title Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL
First Time appeared Miniflux Project
Miniflux Project miniflux
Weaknesses CWE-918
CPEs cpe:2.3:a:miniflux_project:miniflux:*:*:*:*:*:*:*:*
Vendors & Products Miniflux Project
Miniflux Project miniflux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:41.662Z

Reserved: 2026-10-11T01:52:48.773Z

Link: CVE-2026-108735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:17.767

Modified: 2026-10-11T13:17:17.767

Link: CVE-2026-108735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses