Skip to content
Security & Trust

MediaFlow Proxy bug lets outsiders make the server fetch internal pages

CVE-2026-100391 turns a proxy's network position into the attacker's reach. The question is what yours can touch.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
MediaFlow Proxy bug lets outsiders make the server fetch internal pages

AI-generated image for WebPulse. About our images

Key finding

CVSS 3.1 base score: 8.2 (High) (Source: NIST NVD, scored by [email protected] (record updated September 30, 2026))

A proxy borrows its location, and so does anyone who steers it

A proxy is a messenger. You hand it an address, and it fetches the page for you. The messenger is trusted because of where it sits, often inside a private network. That trust is the risk. If a stranger can choose the address, the stranger inherits the messenger's reach.

This is the lesson in CVE-2026-100391, a vulnerability in MediaFlow Proxy. The flaw does not break into anything. It persuades a trusted server to go and look.

What the NVD record says

The U.S. National Vulnerability Database (NVD) published the record on September 25, 2026. It last updated it on September 30. It says MediaFlow Proxy through version 2.4.9 has a server-side request forgery (SSRF) flaw in its /proxy routes.

The cause is missing and incomplete checks on the destination. The destination arrives in a query parameter named d. An outside attacker can put an address of their choosing in that parameter, and the record lists the server's own loopback address and cloud metadata endpoints among the targets. The proxy then hands back the complete responses.

8.2 (High)
CVSS 3.1 base score
Source: NIST NVD, scored by [email protected] (record updated September 30, 2026)
8.8 (High)
CVSS 4.0 base score
Source: NIST NVD, scored by [email protected] (record updated September 30, 2026)
Through 2.4.9
Affected versions
Source: NIST NVD, CVE-2026-100391 (published September 25, 2026)

How the attack works

Normally a proxy fetches public web addresses. A well-built one checks the destination first and refuses anything private. Here, the record says those checks are missing or incomplete.

Two kinds of internal target are named. Loopback is the server's own address, where services meant only for that machine often listen. Cloud metadata endpoints are internal addresses that cloud platforms offer to a running machine so it can learn about itself. On some cloud platforms, they can return temporary credentials. The record does not say what any particular deployment would expose.

The record also says attackers can read full responses. That means the attacker sees the content that comes back, not just whether a request succeeded.

Reading the score in plain words

The CVSS 3.1 vector rates the attack as network-reachable, low complexity, needing no privileges and no user interaction. In practice, no login and no victim clicking a link. Confidentiality impact is rated high. Integrity impact is rated low. The record does not explain the low integrity rating.

VulnCheck assigned both scores. Scores describe severity in general. They do not say whether your deployment is exposed.

What the record does not say

The record does not report exploitation in the wild. It does not name a fixed version. NVD lists a GitHub commit and a VulnCheck advisory as references. The record does not describe the commit as a fix, so confirm that with the maintainer's repository and the advisory.

This is one record for one product. It is not evidence of a wider trend. It is a clear example of a common design problem.

Questions to put to your team

First, do we run MediaFlow Proxy, and which version? Anything at 2.4.9 or earlier falls within the record's scope.

Second, can that server reach cloud metadata addresses or internal-only services? If so, that is what an attacker could read through it.

Third, more broadly: which of our tools fetch URLs on a user's behalf? Previews, importers and proxies all qualify. Who checked what they are allowed to fetch?

A proxy is only as safe as the list of places it refuses to go. Count that list before you count the proxy's features.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.

CVEs in this analysis
CVE-2026-100391
Share this insight