CVE-2025-46339: FreshRSS vulnerable to favicon cache poisoning via proxy

Published Jun 4, 2025
·
Updated

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding a given URL as a feed with the proxy set to an attacker-controlled one and disabled SSL verifying. The favicon hash is computed by hashing the feed URL and the salt, whilst not including the following variables: proxy address, proxy protocol, and whether SSL should be verified. Therefore it's possible to poison a favicon of a given feed by simply intercepting the response of the feed, and changing the website URL to one where a threat actor controls the feed favicon. Feed favicons can be replaced for all users by anyone. Version 1.26.2 fixes the issue.

Affected Software

2 affected components
FreshRSS FreshRSS<1.26.2
FreshRSS FreshRSS<1.26.2

Event History

Jun 4, 2025
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-46339?

CVE-2025-46339 is considered a high-severity vulnerability due to the potential for favicon poisoning.

2

How do I fix CVE-2025-46339?

To fix CVE-2025-46339, update to FreshRSS version 1.26.2 or later.

3

What impact does CVE-2025-46339 have on FreshRSS users?

CVE-2025-46339 allows attackers to manipulate feed favicons by exploiting insecure feed configurations.

4

Is CVE-2025-46339 a remote attack vector?

Yes, CVE-2025-46339 can be exploited remotely if proper security measures are not in place.

5

What is the recommended security practice concerning CVE-2025-46339?

Always ensure SSL verification is enabled and keep FreshRSS updated to avoid vulnerabilities like CVE-2025-46339.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203