HIGHnpm
GHSA-6jcc-xgcr-q3h4· CVE-2025-54888@fedify/fedify has Improper Authentication and Incorrect Authorization
Modified: 2/4/2026
package
pkg:npm/%40fedify/fedify
@fedify/fedify has Improper Authentication and Incorrect Authorization
Modified: 2/4/2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
Modified: 9/10/2026
Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify
Modified: 1/21/2025
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
Modified: 9/10/2026
Server Side Request Forgery (SSRF) attack in Fedify
Modified: 9/10/2026
Fedify has ReDoS Vulnerability in HTML Parsing Regex
Modified: 12/23/2025
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
Modified: 7/28/2026