Security Advisories for lemmy_api_common in cargo
Moderate
about 1 month ago
Lemmy has SSRF in /api/v3/post via Webmention dispatch
cargo
lemmy_api_common
Moderate
about 1 month ago
Lemmy has SSRF and internal image disclosure in post link metadata via unvalidated og:image
cargo
lemmy_api_common
Potential
Moderate
about 1 year ago
Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively use
cargo
lemmy_server
Potential
Moderate
over 1 year ago
Server-Side Request Forgery (SSRF) in activitypub_federation
cargo
activitypub_federation
Potential
High
over 2 years ago
Any authenticated user may obtain private message details from other users on the same instance
cargo
lemmy_server