CVE-2026-108735
Received Received - Intake

Authenticated SSRF in Miniflux via Proxy URL Configuration

Vulnerability report for CVE-2026-108735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
miniflux miniflux 2.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Miniflux versions 2.3.0 to 2.3.3 have a server-side request forgery (SSRF) vulnerability. Authenticated users can exploit this by setting a feed's proxy_url to point to internal or loopback addresses. This bypasses FETCHER_ALLOW_PRIVATE_NETWORKS checks, allowing attackers to probe internal ports and send proxy-style requests to internal services.

Detection Guidance

Check Miniflux configuration for proxy_url settings in feeds pointing to internal or loopback addresses. Review server logs for unusual requests to internal hosts. Use network scanning tools to detect Miniflux instances exposing internal services.

Impact Analysis

An attacker with authenticated access could access internal services, scan internal networks, or interact with services not exposed to the internet. This could lead to data leaks, unauthorized actions on internal systems, or further exploitation of internal vulnerabilities.

Compliance Impact

This vulnerability could violate compliance requirements by exposing internal systems or data to unauthorized access. For GDPR, it may lead to unauthorized data processing or breaches. For HIPAA, it could compromise protected health information by allowing access to internal systems.

Mitigation Strategies

Upgrade Miniflux to a version beyond 2.3.3. Disable proxy_url functionality if not required. Restrict network access to Miniflux instances. Monitor for unauthorized internal requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart