#9314·FreshRSS

[Bug] after updating to 1.30.0, I cannot reach feeds behind proxy

Author: geogirauxCreated Sep 17, 2026Updated Sep 18, 2026
LabelsSecurity :shield:Bug (unconfirmed)

Describe the bug

Due to cloudflare challenges, I'm using a proxy service (scrapingant) with the same setup for some of my feeds :

Image

Since updating (5 days ago), all these feeds are failing, with 2 kinds of lines in the logs, but both about SSL / certificates :

  1. cURL error 60: server certificate verification failed. CAfile: none CRLfile: none [https://www.route-one.net/category/opinion/feed/]
  2. Error fetching content: HTTP code 0: server certificate verification failed. CAfile: none CRLfile: none

When trying to use curl through the server command line, reproducing the insecure flag about SSL verification, it works :

bash
curl -v 'https://www.route-one.net/category/opinion/feed/' --proxy 'https://scrapingant&proxy_country=GB&return_page_source=true:[email protected]:
443' -k
*   Trying 128.140.25.147:443...
* Connected to proxy.scrapingant.com (128.140.25.147) port 443 (#0)
* ALPN: offers http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
*  CAfile: /etc/ssl/certs/ca-certificates.crt
*  CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
* ALPN: server accepted http/1.1
* Proxy certificate:
*  subject: CN=proxy.scrapingant.com
*  start date: Aug 22 04:46:19 2026 GMT
*  expire date: Nov 20 04:46:18 2026 GMT
*  subjectAltName: host "proxy.scrapingant.com" matched cert's "proxy.scrapingant.com"
*  issuer: C=US; O=Let's Encrypt; CN=YR2
*  SSL certificate verify ok.
* allocate connect buffer
* Establish HTTP proxy tunnel to www.route-one.net:443
* Proxy auth using Basic with user 'scrapingant&proxy_country=GB&return_page_source=true'
> CONNECT www.route-one.net:443 HTTP/1.1
> Host: www.route-one.net:443
> Proxy-Authorization: Basic c2NyYXBpbmdhbnQmcHJveHlfY291bnRyeT1HQiZyZXR1cm5fcGFnZV9zb3VyY2U9dHJ1ZTowNjM5MmRhNDhmMGM0NzUzYTRiYmQ3ZjcxYTU5OTI1OQ==
> User-Agent: curl/7.88.1
> Proxy-Connection: Keep-Alive
> 
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
< HTTP/1.1 200 Connection established
< 
* CONNECT phase completed
* CONNECT tunnel established, response 200
* ALPN: offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* ALPN: server accepted h2
* Server certificate:
*  subject: CN=route-one.net
*  start date: Sep 15 17:06:29 2026 GMT
*  expire date: Sep 17 17:06:29 2027 GMT
*  issuer: CN=mitmproxy; O=mitmproxy
*  SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.
* using HTTP/2
* h2h3 [:method: GET]
* h2h3 [:path: /category/opinion/feed/]
* h2h3 [:scheme: https]
* h2h3 [:authority: www.route-one.net]
* h2h3 [user-agent: curl/7.88.1]
* h2h3 [accept: */*]
* Using Stream ID: 1 (easy handle 0x560ca6152e70)
> GET /category/opinion/feed/ HTTP/2
> Host: www.route-one.net
> user-agent: curl/7.88.1
> accept: */*
> 
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
< HTTP/2 200 
< ant-credits-cost: 2
< ant-original-header-alt-svc: h3=":443"; ma=86400
< ant-original-header-cache-control: max-age=3600
< ant-original-header-cf-cache-status: DYNAMIC
< ant-original-header-cf-ray: a3c9b418a8b1134c-LHR
< ant-original-header-content-encoding: gzip
< ant-original-header-content-length: 18970
< ant-original-header-content-type: application/rss+xml; charset=UTF-8
< ant-original-header-date: Thu, 17 Sep 2026 17:06:48 GMT
< ant-original-header-expires: Thu, 17 Sep 2026 18:06:47 GMT
< ant-original-header-last-modified: Thu, 17 Sep 2026 15:52:13 GMT
< ant-original-header-link: <https://www.route-one.net/wp-json/>; rel="https://api.w.org/", <https://www.route-one.net/wp-json/wp/v2/categories/10>; rel="alternate"; title="JSON"; type="application/json", <https://www.route-one.net/category/opinion/>; rel="canonical"
< ant-original-header-nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
< ant-original-header-report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3y6N3wquWk3i4ZAIm9cZz2m%2FgD0vMdicH3ep2VgbWNAITHI%2BTswNgWTkXvwjzeBOws%2FizpnYaAf5f72kQ4Mkzb5M5ggbq0XoHh0WVB2EwUmEBhg5NID7m1UUKSpf1z8XHEMORA%3D%3D"}]}
< ant-original-header-server: cloudflare
< ant-original-header-vary: Accept-Encoding
< ant-page-status-code: 200
< content-type: text/xml; charset=utf-8
< date: Thu, 17 Sep 2026 17:06:29 GMT
< server: uvicorn
< vary: Accept-Encoding
< content-length: 58716
< 
<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
        xmlns:content="http://purl.org/rss/1.0/modules/content/"
        xmlns:wfw="http://wellformedweb.org/CommentAPI/"
        xmlns:dc="http://purl.org/dc/elements/1.1/"
        xmlns:atom="http://www.w3.org/2005/Atom"
        xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
        xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
        xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
        <title>Opinion- the industry&#039;s take on coach, bus and minibus news - routeone</title>
        <atom:link href="https://www.route-one.net/category/opinion/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.route-one.net/category/opinion/</link>

To Reproduce

Might be specific to my setup, sorry, but as it works from command line I narrowed it down to FreshRSS I'd like to know if I'm missing something obvious, like for instance differences between the -k flag of the command line and the SSL verification option of the web interface

Expected behavior

No response

FreshRSS version

1.30.0

System information

  • installation on a shared server (not admin)
  • PHP 8.3.33
  • curl 7.88.1
  • webserver type : Apache

Additional context

No response