CVE-2025-59949: FreshRSS has Logout CSRF that Leads to DoS via <track src>
Published Dec 18, 2025
·Updated
FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.
Affected Software
2 affected components
FreshRSS<1.27.1
FreshRSS FreshRSS<1.27.1
Remediation
Patch Available
Patch Available
Event History
Dec 18, 2025
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59949?
CVE-2025-59949 is a critical vulnerability that can lead to denial of service due to a logout cross-site request forgery issue.
2
How do I fix CVE-2025-59949?
To fix CVE-2025-59949, upgrade to FreshRSS version 1.27.1 or later.
3
Which versions of FreshRSS are affected by CVE-2025-59949?
FreshRSS versions prior to 1.27.1 are affected by CVE-2025-59949.
4
What impact does CVE-2025-59949 have on FreshRSS users?
CVE-2025-59949 can allow attackers to cause denial of service for FreshRSS users.
5
Is there any patch available for CVE-2025-59949?
Yes, version 1.27.1 of FreshRSS includes a patch for CVE-2025-59949.