FreshRSS Denial-of-Service Vulnerability via Malicious Feed Entry

Vulnerability

A denial-of-service vulnerability has been identified in FreshRSS versions prior to 1.26.2. This issue causes users to be repeatedly logged out after fetching a malicious feed entry. The vulnerability takes advantage of the application's feed handling, leading to a disruptive logout loop for the affected user.

Impact

Exploitation of this vulnerability causes a user's account to be logged out repeatedly, disrupting their session and causing inconvenience.

Reproduction

To reproduce this vulnerability, a feed entry must be crafted that includes a logout URL. This can be done by embedding an iframe that redirects to the logout URL, effectively logging the user out when the feed is fetched. Once the malicious feed entry is loaded, the user will experience repeated logouts.

Remediation

Users can upgrade to FreshRSS version 1.26.2 or later, where this vulnerability has been patched.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
7.7
remediation
7.7
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.