{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amediaflowproxy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mediaflow:proxy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-100391"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MediaFlow Proxy (\u003c= 2.4.9)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["MediaFlow"],"content_html":"\u003cp\u003eMediaFlow Proxy through version 2.4.9 contains a high-severity server-side request forgery (SSRF) vulnerability. The flaw exists within the /proxy endpoint, where the application fails to perform sufficient validation on the 'd' query parameter. This allows an unauthenticated remote attacker to craft requests that force the proxy server to retrieve data from arbitrary internal or external URLs.\u003c/p\u003e\n\u003cp\u003eDefenders must be aware that this vulnerability enables attackers to interact with internal-only services, including loopback (127.0.0.1) addresses and cloud provider metadata services (e.g., 169.254.169.254), to potentially exfiltrate sensitive environment credentials or configuration data. Because this vulnerability exists in the request routing logic, it does not require prior authentication, making it a significant risk for internet-facing instances of MediaFlow Proxy.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass network perimeters, probe internal network segments, and access protected cloud instance metadata services, which often contain highly sensitive IAM credentials and environment-specific configuration secrets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade MediaFlow Proxy to a patched version beyond 2.4.9 immediately to remediate CVE-2026-100391.\u003c/li\u003e\n\u003cli\u003eUntil patching is complete, restrict access to the /proxy endpoint via Web Application Firewall (WAF) or reverse proxy configurations.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous requests to the /proxy endpoint that contain internal-only URI schemes, IP addresses, or metadata service paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T22:55:46Z","date_published":"2026-09-25T22:55:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mediaflow-proxy-ssrf/","summary":"MediaFlow Proxy versions 2.4.9 and earlier are vulnerable to server-side request forgery (SSRF) via the /proxy route, allowing unauthorized access to internal resources and cloud metadata services.","title":"CVE-2026-100391: Server-Side Request Forgery in MediaFlow Proxy","url":"https://feed.craftedsignal.io/briefs/2026-09-mediaflow-proxy-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mediaflow:proxy:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}