CVE-2026-100391 – MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation

​CVE ID :CVE-2026-100391

Published : Sept. 25, 2026, 8:13 p.m. | 1 hour, 16 minutes ago

Description :MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

Severity: 8.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More