OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-100391 (CVSS 8.8)

NVD · officialPublished Sep 25, 2026Risk 37/100

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source