GHSA-5j62-5j8p-jpqhHighCVSS 8.2

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

🔗 References (6)