CVE-2026-34148

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
06/04/2026
Last modified:
25/04/2026

Description

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* 1.9.6 (excluding)
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* 1.10.0 (including) 1.10.5 (excluding)
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* 2.0.0 (including) 2.0.8 (excluding)
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* 2.1.0 (including) 2.1.1 (excluding)
cpe:2.3:a:fedify:fedify\/vocab-runtime:*:*:*:*:*:node.js:*:* 2.0.8 (excluding)
cpe:2.3:a:fedify:fedify\/vocab-runtime:*:*:*:*:*:node.js:*:* 2.1.0 (including) 2.1.1 (excluding)