Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gm9m-gwc4-hwgp | Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution |
Sat, 25 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedify fedify\/fedify
Fedify fedify\/vocab-runtime |
|
| CPEs | cpe:2.3:a:fedify:vocab-runtime:*:*:*:*:*:*:*:* cpe:2.3:a:fedify:vocab-runtime:2.1.0:*:*:*:*:*:*:* |
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* cpe:2.3:a:fedify:fedify\/vocab-runtime:*:*:*:*:*:node.js:*:* |
| Vendors & Products |
Fedify fedify\/fedify
Fedify fedify\/vocab-runtime |
Tue, 14 Apr 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fedify:fedify:*:*:*:*:*:*:*:* cpe:2.3:a:fedify:vocab-runtime:*:*:*:*:*:*:*:* cpe:2.3:a:fedify:vocab-runtime:2.1.0:*:*:*:*:*:*:* |
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedify
Fedify fedify Fedify vocab-runtime |
|
| Vendors & Products |
Fedify
Fedify fedify Fedify vocab-runtime |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1. | |
| Title | Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T14:25:51.368Z
Reserved: 2026-03-25T20:12:04.195Z
Link: CVE-2026-34148
Updated: 2026-04-06T15:35:07.905Z
Status : Analyzed
Published: 2026-04-06T16:16:34.387
Modified: 2026-04-25T18:03:02.780
Link: CVE-2026-34148
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:16Z
Github GHSA