HarborGuard / CVE
Back to search
HIGHCVE-2026-34148Published Modified CNA GitHub_M

CVE-2026-34148: Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
2
Affected packages
  • @fedify / fedify
    < 1.9.6 · >= 1.10.0, < 1.10.5 · >= 2.0.0, < 2.0.8 · >= 2.1.0, < 2.1.1
  • @fedify / vocab-runtime
    < 2.0.8 · >= 2.1.0, < 2.1.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H