If you found a vulnerability that you deem too sensitive to disclose publicly in a Github issue, please create a private security advisory here: https://github.com/Athou/commafeed/security/advisories
Security: Athou/commafeed
Security
SECURITY.md
-
Cross-Tenant Feed-Entry Content Disclosure via POST /rest/entry/starGHSA-prfv-88mm-5gpg published
Aug 22, 2026 by AthouModerate -
Host header injection in password reset/logout functionalityGHSA-hp8h-jqfm-v7x5 published
Aug 17, 2026 by AthouHigh -
SSRF guard missing IPv6 transition address extraction (NAT64/6to4/Teredo)GHSA-q5qw-345w-55xg published
Aug 11, 2026 by AthouModerate -
Missing URL scheme validation in feed entry URLs allows injection of javascript: URLs (conditional XSS)GHSA-44pq-9929-f8mq published
Aug 3, 2026 by AthouLow -
`block-local-addresses` SSRF control misses IPv6 ULA (`fc00::/7`) and RFC6598 CGNAT (`100.64.0.0/10`): even with the control enabled, the server can reach internal services on those rangesGHSA-hgrr-mjfp-gmr6 published
Jul 5, 2026 by AthouModerate -
XML Entity Expansion (Billion Laughs) DoS via OPML import allows any authenticated user to crash the serverGHSA-83jp-rww3-57rr published
Jun 13, 2026 by AthouModerate
Learn more about advisories related to Athou/commafeed in the GitHub Advisory Database