FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0.
History

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Freshrss
Freshrss freshrss
Vendors & Products Freshrss
Freshrss freshrss

Mon, 29 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 27 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
Description FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0.
Title FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-26T23:46:53.337Z

Updated: 2025-12-29T16:51:47.993Z

Reserved: 2025-12-15T19:06:04.109Z

Link: CVE-2025-68148

cve-icon Vulnrichment

Updated: 2025-12-29T16:44:26.096Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-27T00:15:42.167

Modified: 2025-12-29T17:15:46.700

Link: CVE-2025-68148

cve-icon Redhat

No data.