CVE-2026-21885: Miniflux Project Miniflux
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in feed entry content, including internal addresses (e.g., localhost, private RFC1918 ranges, or link-local metadata endpoints). Requesting the resulting `/proxy/...` URL makes Miniflux fetch and return the internal response. Version 2.2.16 fixes the issue.
Affected products
- Miniflux Project Miniflux: from 2.0.0, before 2.2.16 (fixed in 2.2.16)
Published 2026-01-08. Last modified 2026-06-17.