CVE-2026-34148 Details
Description
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.
A denial-of-service vulnerability has been identified in the Fedify TypeScript library, specifically in versions prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1. The issue arises because the library's remote and authenticated document loaders follow HTTP redirects recursively without a maximum redirect limit or detection of visited URL loops. This flaw allows an attacker controlling a remote ActivityPub key or actor URL to exploit the server into making numerous outbound requests, consuming resources and causing a denial-of-service condition.
Users can upgrade to Fedify versions 1.9.6, 1.10.5, 2.0.8, or 2.1.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/fedify-dev/fedify/security/advisories/GHSA-gm9m-gwc4-hwgp | CISA-ADP | ExploitVendor Advisory |
| https://github.com/fedify-dev/fedify/releases/tag/1.10.5 | [email protected] | Release Notes |
| https://github.com/fedify-dev/fedify/releases/tag/1.9.6 | [email protected] | Release Notes |
| https://github.com/fedify-dev/fedify/releases/tag/2.0.8 | [email protected] | Release Notes |
| https://github.com/fedify-dev/fedify/releases/tag/2.1.1 | [email protected] | Release Notes |
| https://github.com/fedify-dev/fedify/security/advisories/GHSA-gm9m-gwc4-hwgp | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fedify fedify/fedify | < 1.9.6 >= 1.10.0, < 1.10.5 >= 2.0.0, < 2.0.8 >= 2.1.0, < 2.1.1 |
CPE
Remediation
| |
| fedify fedify/vocab-runtime | < 2.0.8 >= 2.1.0, < 2.1.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2026 | Reanalysis | [email protected] |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | CVE Modified | [email protected] |
| Apr 6, 2026 | New CVE Received | [email protected] |
| Apr 6, 2026 | CVE Modified | CISA-ADP |