CVE-2026-21885

MEDIUM6.5EPSS 0.05%

Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources in miniflux.app

Published: 1/7/2026Modified: 3/3/2026
Also known as:GHSA-xwh2-742g-w3wpGO-2026-4287

Description

Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources in miniflux.app

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (4)