PT-2026-2121 · Miniflux+1 · Miniflux+1

·

CVE-2026-21885

·

Published

2026-01-07

·

Updated

2026-07-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Miniflux versions prior to 2.2.16
Description Miniflux is an open source feed reader. Prior to version 2.2.16, the media proxy endpoint, GET /proxy/{encodedDigest}/{encodedURL}, can be exploited to perform Server-Side Request Forgery (SSRF). An authenticated user can manipulate Miniflux to create a signed proxy URL for media URLs specified by the attacker within feed entry content. These URLs can include internal addresses, such as localhost, private RFC1918 ranges, or link-local metadata endpoints. Accessing the generated /proxy/... URL causes Miniflux to retrieve and return the response from the internal address.
Recommendations Upgrade to Miniflux version 2.2.16 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21885
GHSA-XWH2-742G-W3WP
GO-2026-4287
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0142-1

Affected Products

Debian
Miniflux