Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-34148 Details

Description

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-400Uncontrolled Resource Consumption[email protected]
CWE-770Allocation of Resources Without Limits or Throttling[email protected]

Affected Products

ProductVersions
fedify fedify/fedify
< 1.9.6
>= 1.10.0, < 1.10.5
>= 2.0.0, < 2.0.8
>= 2.1.0, < 2.1.1

CPE

  • cpe:2.3:a:fedify:fedify/fedify:*:*:*:*:*:node.js:*:*

Remediation

  • No remediation found in references.
fedify fedify/vocab-runtime
< 2.0.8
>= 2.1.0, < 2.1.1

CPE

  • cpe:2.3:a:fedify:fedify/vocab-runtime:*:*:*:*:*:node.js:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-34148
NVD Published Date:
Apr 6, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2026-34148 Details - Not Deferred