HIGH7.5npm
GHSA-gm9m-gwc4-hwgp· CVE-2026-34148Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
Modified: 9/10/2026
package
pkg:npm/%40fedify/vocab-runtime
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
Modified: 9/10/2026
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
Modified: 7/28/2026