<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 10:27:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265183</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265183</link>
      <description>EUVD-2026-265183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265183</guid>
    </item>
    <item>
      <title>fkie_cve-2026-21885</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21885</link>
      <description>&lt;p&gt;Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-21885</guid>
    </item>
    <item>
      <title>GHSA-xwh2-742g-w3wp — Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xwh2-742g-w3wp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: miniflux.app/v2&lt;/p&gt;
&lt;p&gt;### Summary
Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response.&lt;/p&gt;
&lt;p&gt;### Details
- **Vulnerable route**: `GET /proxy/{encodedDigest}/{encodedURL}` (accessible without authentication, but requires a server-generated HMAC-signed URL)
- **Handler**: `internal/ui/proxy.go` (`(*handler).mediaProxy`)
- **Trigger**: entry content is rewritten to proxy media URLs (e.g., `mediaproxy.RewriteDocumentWithAbsoluteProxyURL(...)`), producing signed `/proxy/...` URLs.
- **Root cause**: the proxy validates the URL scheme and HMAC signature, but does not restrict target hosts/IPs. As a result, requests to loopback/private/link-local addresses are allowed and fetched by the server.&lt;/p&gt;
&lt;p&gt;### PoC
1) Run Miniflux 2.2.15 with default configuration (media proxy enabled by default: `MEDIA_PROXY_MODE=http-only`).&lt;/p&gt;
&lt;p&gt;2) Log in with any normal user account.&lt;/p&gt;
&lt;p&gt;3) Subscribe to a feed you control that contains an entry with an image URL pointing to an internal address reachable from the Miniflux server, e.g.:
   - `&amp;lt;img src=&amp;#34;http://&amp;lt;internal-target&amp;gt;/secret&amp;#34;&amp;gt;`
   (Note: `&amp;lt;internal-target&amp;gt;` must be reac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: miniflux.app/v2&lt;/p&gt;
&lt;p&gt;### Summary
Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response.&lt;/p&gt;
&lt;p&gt;### Details
- **Vulnerable route**: `GET /proxy/{encodedDigest}/{encodedURL}` (accessible without authentication, but requires a server-generated HMAC-signed URL)
- **Handler**: `internal/ui/proxy.go` (`(*handler).mediaProxy`)
- **Trigger**: entry content is rewritten to proxy media URLs (e.g., `mediaproxy.RewriteDocumentWithAbsoluteProxyURL(...)`), producing signed `/proxy/...` URLs.
- **Root cause**: the proxy validates the URL scheme and HMAC signature, but does not restrict target hosts/IPs. As a result, requests to loopback/private/link-local addresses are allowed and fetched by the server.&lt;/p&gt;
&lt;p&gt;### PoC
1) Run Miniflux 2.2.15 with default configuration (media proxy enabled by default: `MEDIA_PROXY_MODE=http-only`).&lt;/p&gt;
&lt;p&gt;2) Log in with any normal user account.&lt;/p&gt;
&lt;p&gt;3) Subscribe to a feed you control that contains an entry with an image URL pointing to an internal address reachable from the Miniflux server, e.g.:
   - `&amp;lt;img src=&amp;#34;http://&amp;lt;internal-target&amp;gt;/secret&amp;#34;&amp;gt;`
   (Note: `&amp;lt;internal-target&amp;gt;` must be reac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xwh2-742g-w3wp</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-21885</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21885</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: miniflux, Ubuntu:25.10: miniflux, Ubuntu:Pro:26.04:LTS: miniflux&lt;/p&gt;
&lt;p&gt;Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: miniflux, Ubuntu:25.10: miniflux, Ubuntu:Pro:26.04:LTS: miniflux&lt;/p&gt;
&lt;p&gt;Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux&amp;#39;s media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21885</guid>
    </item>
  </channel>
</rss>
