Security Advisories for @fedify/fedify in npm
High
about 1 month ago
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
npm
@fedify/vocab-runtime, @fedify/fedify
High
3 months ago
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
npm
@fedify/fedify
High
5 months ago
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
npm
@fedify/vocab-runtime, @fedify/fedify
High
about 1 year ago
@fedify/fedify has Improper Authentication and Incorrect Authorization
npm
@fedify/fedify
Moderate
over 1 year ago
Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify
npm
@fedify/fedify