PT-2026-99111 · Unknown · Mediaflow-Proxy

·

CVE-2026-100391

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaFlow Proxy versions prior to 2.5.0
Description An issue exists in the '/proxy' endpoint where missing and incomplete destination validation of the d query parameter allows for server-side request forgery (SSRF). This occurs when a server is tricked into making requests to an unintended location. Remote attackers can provide arbitrary internal URLs, such as loopback addresses or cloud metadata endpoints, to retrieve full responses from the proxy server.
Recommendations Update to a version newer than 2.4.9. As a temporary mitigation, restrict access to the '/proxy' endpoint or validate the d parameter to prevent requests to internal network addresses.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100391

Affected Products

Mediaflow-Proxy