Sceawere
Vulnerability Detail
CVE-2026-108735UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Miniflux SSRF via Proxy URL
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- miniflux
- Product
- miniflux
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:17.767Z",
"pubdate": "2026-10-11T13:17:17.767Z",
"executiveSummary": "Miniflux versions 2.3.0 through 2.3.3 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. The flaw resides in the application's feed management functionality, specifically concerning the handling of the proxy_url parameter.\nBy manipulating this field, an authenticated user can force the server to initiate arbitrary HTTP requests directed at internal network resources or the host's loopback interface.\nThis vulnerability bypasses existing security controls, such as the FETCHER_ALLOW_PRIVATE_NETWORKS configuration, which is intended to restrict outbound requests to internal IP ranges.\nThe primary impact involves unauthorized service discovery, port scanning of internal infrastructure, and the potential to interact with vulnerable internal APIs or services that are otherwise protected by network perimeter defenses.\nSuccessful exploitation requires the attacker to possess authenticated access to the Miniflux instance. Once authenticated, the attacker can leverage the server's identity to bridge the gap between external access and the internal network, creating a significant security risk for the underlying infrastructure hosting the application.",
"technicalDetails": "The vulnerability originates from inadequate validation and improper sanitization of the proxy_url parameter within the Miniflux feed configuration process. In affected versions (2.3.0 to 2.3.3), the application logic fails to enforce network access restrictions when a user-supplied proxy URL is processed by the internal fetcher.\nWhile Miniflux provides a configuration setting identified as FETCHER_ALLOW_PRIVATE_NETWORKS to restrict outbound requests, the implementation of this control is bypassed when utilizing the proxy_url feature. The application allows an authenticated user to specify an arbitrary address, including loopback (127.0.0.1) or RFC 1918 private network addresses, which are then passed to the underlying network transport layer.\nThe attack flow follows a structured exploitation path: First, an attacker authenticates to the Miniflux dashboard. Second, the attacker creates or modifies an existing feed, setting the proxy_url field to a target internal destination, such as http://127.0.0.1:port or a specific internal management interface. Third, the attacker initiates a refresh or fetch operation for the modified feed. The application's backend processes this request, utilizing the attacker-supplied URL to proxy the request. Because the request originates from the application server itself, it bypasses network-level firewalls that would otherwise block direct access to these internal services.\nThe technical core of this issue lies in the lack of robust server-side validation of the proxy destination. The application fails to resolve the provided hostname or IP address against a denylist or allowlist prior to initiating the network connection. This permits the server to perform requests on behalf of the attacker, effectively turning the Miniflux instance into a proxy for internal network reconnaissance and potential exploitation of further services.\nPost-exploitation, the attacker can observe responses from internal services if they are reflected in the feed's error messages or status updates. By iterating through ports and targets, an attacker can map the internal network topology, identify running services, and execute unauthorized requests against internal APIs that assume the request is trustworthy due to its origin from the application server."
}