CVE-2026-34148
HIGHFedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
Title source: cnaDescription
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.
References (5)
Core 5
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/fedify-dev/fedify/releases/tag/2.0.8
X_Refsource_Confirm x_refsource_confirm
https://github.com/fedify-dev/fedify/security/advisories/GHSA-gm9m-gwc4-hwgp
X_Refsource_Misc x_refsource_misc
https://github.com/fedify-dev/fedify/releases/tag/1.10.5
X_Refsource_Misc x_refsource_misc
https://github.com/fedify-dev/fedify/releases/tag/1.9.6
X_Refsource_Misc x_refsource_misc
https://github.com/fedify-dev/fedify/releases/tag/2.1.1
Scores
CVSS v3
7.5
EPSS
0.0055
EPSS Percentile
41.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
CWE-770
Status
published
Products (17)
@fedify/fedify
< 1.9.6
@fedify/fedify
>= 1.10.0, < 1.10.5
@fedify/fedify
>= 2.0.0, < 2.0.8
@fedify/fedify
>= 2.1.0, < 2.1.1
@fedify/vocab-runtime
< 2.0.8
@fedify/vocab-runtime
>= 2.1.0, < 2.1.1
fedify/fedify
< 1.9.5
fedify/fedify
0 - 1.9.6npm
fedify/fedify
1.10.0 - 1.10.5npm
fedify/fedify
2.0.0 - 2.0.8npm
... and 7 more
Published
Apr 06, 2026
Tracked Since
Apr 06, 2026