Security: fedify-dev/fedify
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network ResourcesGHSA-hqph-j65v-8cq5 published
Jul 18, 2026 by dahliaHigh -
Incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 rangesGHSA-xw9q-2mv6-9fr8 published
Jun 8, 2026 by dahliaHigh -
Linked Data Signature Bypass via JSON-LD Named-Graph RestructuringGHSA-9rfg-v8g9-9367 published
May 20, 2026 by dahliaHigh -
Resource exhaustion caused by unbounded redirect following during remote key/document resolutionGHSA-gm9m-gwc4-hwgp published
Apr 4, 2026 by dahliaHigh -
ReDoS Vulnerability in HTML Parsing RegexGHSA-rchf-xwx2-hm93 published
Dec 20, 2025 by dahliaHigh -
Improper Authentication and Incorrect Authorization in @fedify/fedifyGHSA-6jcc-xgcr-q3h4 published
Aug 8, 2025 by dahliaHigh -
Infinite loop and Blind SSRF found inside the WebFinger mechanismGHSA-c59p-wq67-24wx published
Jan 20, 2025 by dahliaModerate -
Potential for access to internal network resourcesGHSA-p9cg-vqcc-grcx published
Jul 5, 2024 by dahliaHigh