- Python 80%
- HTML 16.7%
- JavaScript 2.9%
- Makefile 0.2%
- Dockerfile 0.2%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
The SSRF guard on /proxy/forward only checked whether the hostname was already a numeric IP literal. A hostname that resolves to a private, loopback, or link-local address (like *.nip.io mapping straight to an IP) walked right through the try/except and was never checked, since DNS resolution never happened. /proxy/stream had no guard at all, so any destination reached it unchecked. Both now resolve the hostname first and check every address it resolves to. Numeric IP literals skip the DNS lookup and are checked directly, same as before. The allowlist, denylist, and scheme checks on /forward are unchanged. Left the HLS, MPD, and transcode endpoints out of this PR. Some of them pull in URLs parsed out of manifest content rather than a single query param, which is a different problem from what's fixed here and needs its own look. Added tests that hit the guard directly: a private IP literal, a hostname that resolves to loopback (localhost), a normal public host, and the full /forward check with the hostname bypass. Confirmed the private-IP-literal-only version lets a real nip.io hostname through unblocked, and the fixed version rejects it. |
||
| .github | ||
| docs | ||
| mediaflow_proxy | ||
| tests | ||
| .dockerignore | ||
| .gitignore | ||
| docker-compose.portainer | ||
| docker-compose.yml | ||
| Dockerfile | ||
| heroku.yml | ||
| LICENSE | ||
| Makefile | ||
| mkdocs.yml | ||
| pyproject.toml | ||
| README.md | ||
| uv.lock | ||
MediaFlow Proxy
MediaFlow Proxy is a streaming proxy for HTTP(S), HLS (M3U8), and MPEG-DASH—including ClearKey DRM and real-time DASH-to-HLS conversion. It also supports IPTV (Xtream Codes), Acestream, Telegram media, transcoding, and advanced routing.
Full documentation: mhdzumair.github.io/mediaflow-proxy (built from the docs/ folder with MkDocs Material).
Quick start
docker run -p 8888:8888 -e API_PASSWORD=your_password mhdzumair/mediaflow-proxy
Prefer not to self-host? A managed MediaFlow Proxy instance is available via ElfHosted, bundled with debrid and Stremio addons in their streaming personal-stacks (7-day trial).
Highlights
- DASH (ClearKey) to HLS, HLS manipulation, generic HTTP(S) proxy with custom headers
- Xtream Codes API proxy, Acestream, Telegram (MTProto) streaming
- Optional GPU transcoding (fMP4 H.264/AAC), pre-buffering, segment skip, stream transformers
- Redis-backed rate limiting, encrypted URL generation, reverse-proxy–friendly forwarded headers
Docs and source
| Resource | Link |
|---|---|
| User & operator manual | Documentation site |
| Markdown sources | docs/ in this repository |
| Build docs locally | uv sync --group docs then uv run mkdocs serve |
High-throughput alternative ⚡
For lower memory usage and higher throughput — especially on constrained hardware (small VPS, NAS, Raspberry Pi) — see MediaFlow Proxy Light, a Rust reimplementation that is fully API-compatible with this proxy. Benchmarks show 7–8× less memory, 1.7–3.4× less CPU per request, and up to 4× higher throughput. Existing tokens, encrypted URLs, and client integrations work without changes.
Contributing
Contributions are welcome! see Contributing in the docs and open a Pull Request on GitHub.
License
Disclaimer
This project is for educational purposes only. The developers of MediaFlow Proxy are not responsible for any misuse of this software. Please ensure that you have the necessary permissions to access and use the media streams you are proxying.