<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:mediaflow:proxy:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amediaflowproxy/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 22:55:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amediaflowproxy/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-100391: Server-Side Request Forgery in MediaFlow Proxy</title><link>https://feed.craftedsignal.io/briefs/2026-09-mediaflow-proxy-ssrf/</link><pubDate>Fri, 25 Sep 2026 22:55:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mediaflow-proxy-ssrf/</guid><description>MediaFlow Proxy versions 2.4.9 and earlier are vulnerable to server-side request forgery (SSRF) via the /proxy route, allowing unauthorized access to internal resources and cloud metadata services.</description><content:encoded><![CDATA[<p>MediaFlow Proxy through version 2.4.9 contains a high-severity server-side request forgery (SSRF) vulnerability. The flaw exists within the /proxy endpoint, where the application fails to perform sufficient validation on the 'd' query parameter. This allows an unauthenticated remote attacker to craft requests that force the proxy server to retrieve data from arbitrary internal or external URLs.</p>
<p>Defenders must be aware that this vulnerability enables attackers to interact with internal-only services, including loopback (127.0.0.1) addresses and cloud provider metadata services (e.g., 169.254.169.254), to potentially exfiltrate sensitive environment credentials or configuration data. Because this vulnerability exists in the request routing logic, it does not require prior authentication, making it a significant risk for internet-facing instances of MediaFlow Proxy.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to bypass network perimeters, probe internal network segments, and access protected cloud instance metadata services, which often contain highly sensitive IAM credentials and environment-specific configuration secrets.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade MediaFlow Proxy to a patched version beyond 2.4.9 immediately to remediate CVE-2026-100391.</li>
<li>Until patching is complete, restrict access to the /proxy endpoint via Web Application Firewall (WAF) or reverse proxy configurations.</li>
<li>Audit web server access logs for anomalous requests to the /proxy endpoint that contain internal-only URI schemes, IP addresses, or metadata service paths.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>web-vulnerability</category></item></channel></rss>