VDB
Sign up

package

npm/@fedify/vocab-runtime

pkg:npm/%40fedify/vocab-runtime

HIGH7.5npm
GHSA-gm9m-gwc4-hwgp· CVE-2026-34148

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

Modified: 9/10/2026

HIGH8.6npm
GHSA-xw9q-2mv6-9fr8· CVE-2026-50131

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Modified: 7/28/2026