Server-Side Request Forgery in MediaFlow Proxy Affects Internal URL Security
CVE-2026-100391

8.8HIGH

Key Information:

Vendor

Mhdzumair

Vendor
CVE Published:
25 September 2026

What is CVE-2026-100391?

MediaFlow Proxy version 2.4.9 has a vulnerability that allows remote attackers to execute server-side request forgery (SSRF) due to missing and improper validation of the destination in the query parameter. This flaw can be exploited to access arbitrary internal URLs, including sensitive endpoints like loopback and cloud metadata services, potentially leading to unauthorized data exposure from the proxy server.

Affected Version(s)

mediaflow-proxy 0 <= 2.4.9

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dilshod Gofurov
.