FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0.
History

Sat, 27 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
Description FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0.
Title FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-26T23:46:53.337Z

Reserved: 2025-12-15T19:06:04.109Z

Link: CVE-2025-68148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-27T00:15:42.167

Modified: 2025-12-27T00:15:42.167

Link: CVE-2025-68148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.