CVE-2026-34148

HIGH

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

Title source: cna
STIX 2.1

Description

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 18.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-770
Status published
Products (13)
@fedify/fedify < 1.9.6
@fedify/fedify >= 1.10.0, < 1.10.5
@fedify/fedify >= 2.0.0, < 2.0.8
@fedify/fedify >= 2.1.0, < 2.1.1
@fedify/vocab-runtime < 2.0.8
@fedify/vocab-runtime >= 2.1.0, < 2.1.1
fedify/fedify < 1.9.5
fedify/fedify 0 - 1.9.6npm
fedify/fedify\/fedify < 1.9.6
fedify/fedify\/vocab-runtime < 2.0.8
... and 3 more
Published Apr 06, 2026
Tracked Since Apr 06, 2026