CVE-2026-100391: Mhdzumair Mediaflow-Proxy
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.
Affected products
- Mhdzumair Mediaflow-Proxy: up to and including 2.4.9
Published 2026-09-25. Last modified 2026-10-05.