Description
Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Internal network exposure via SSRF
Action: Apply patch
AI Analysis

Impact

Miniflux version 2.3.0 through 2.3.3 contains a server‑side request forgery vulnerability that allows an authenticated user to configure a feed’s proxy_url to an arbitrary address. By pointing the proxy_url at loopback or other internal hosts, the application bypasses the FETCHER_ALLOW_PRIVATE_NETWORKS check and can issue proxy‑style requests to services inside the internal network. This grants the attacker the ability to probe internal ports, read data, and potentially execute lateral commands, exposing the internal network to enumeration and compromise.

Affected Systems

The vulnerability affects the Miniflux application as distributed by miniflux_project. All releases from 2.3.0 up to and including 2.3.3 are impacted. No specific operating system or environment restrictions are listed; the issue is inherent to the application logic in the mentioned version range.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, so the current exploitation probability cannot be inferred from that metric. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, attackers must first compromise or log into a Miniflux instance. From there, the ability to change the proxy_url property provides broad internal network access, increasing the potential impact if the internal network hosts are sensitive or contain further exposes.

Generated by OpenCVE AI on October 11, 2026 at 13:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Miniflux release (2.4 or newer) which removes the ability to configure per‑feed proxy URLs or enforces proper network checks.
  • If an upgrade is not immediately possible, disable the per‑feed proxy_url feature by removing or restricting the corresponding configuration in the application settings, or enforce a whitelist of allowed proxy hosts outside the internal network.
  • Implement network monitoring to detect outbound HTTP(S) requests from the Miniflux process to internal IP ranges or private addresses, and investigate any unexpected traffic promptly.

Generated by OpenCVE AI on October 11, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
Title Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL
First Time appeared Miniflux Project
Miniflux Project miniflux
Weaknesses CWE-918
CPEs cpe:2.3:a:miniflux_project:miniflux:*:*:*:*:*:*:*:*
Vendors & Products Miniflux Project
Miniflux Project miniflux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Miniflux Project Miniflux
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:41.662Z

Reserved: 2026-10-11T01:52:48.773Z

Link: CVE-2026-108735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:17.767

Modified: 2026-10-11T13:17:17.767

Link: CVE-2026-108735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)