CVE-2025-68148: FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68148?
CVE-2025-68148 is classified as a high severity vulnerability due to its potential to globally deny access to feeds for the majority of users.
How do I fix CVE-2025-68148?
To mitigate CVE-2025-68148, upgrade FreshRSS to version 1.28.0 or later, which addresses the vulnerability.
Who is affected by CVE-2025-68148?
CVE-2025-68148 affects all FreshRSS users running versions between 1.27.0 and prior to 1.28.0.
What is the impact of CVE-2025-68148?
The impact of CVE-2025-68148 is that it can make FreshRSS instances unusable by denying access to feeds.
Is CVE-2025-68148 being actively exploited?
As of the current information, there are no specific indications that CVE-2025-68148 is being actively exploited.