<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:04:21.301290+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264271</id>
    <title>EUVD-2026-264271</title>
    <updated>2026-10-06T10:04:21.355232+00:00</updated>
    <content>EUVD-2026-264271</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68475</id>
    <title>fkie_cve-2025-68475</title>
    <updated>2026-10-06T10:04:21.355298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rchf-xwx2-hm93</id>
    <title>GHSA-rchf-xwx2-hm93 — Fedify has ReDoS Vulnerability in HTML Parsing Regex</title>
    <updated>2026-10-06T10:04:21.355369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @fedify/fedify</p>
<p>Hi Fedify team! 👋</p>
<p>Thank you for your work on Fedify—it's a fantastic library for building federated applications. While reviewing the codebase, I discovered a Regular Expression Denial of Service (ReDoS) vulnerability that I'd like to report. I hope this helps improve the project's security.</p>
<p>---</p>
<p>## Summary</p>
<p>A Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at `packages/fedify/src/runtime/docloader.ts:259` contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses.</p>
<p>**An attacker-controlled federated server can respond with a small (~170 bytes) malicious HTML payload that blocks the victim's Node.js event loop for 14+ seconds, causing a Denial of Service.**</p>
<p>| Field | Value |
|-------|-------|
| **CWE** | CWE-1333 (Inefficient Regular Expression Complexity) |</p>
<p>---</p>
<p>## Details</p>
<p>### Vulnerable Code</p>
<p>The vulnerability is located in `packages/fedify/src/runtime/docloader.ts`, lines 258-264:</p>
<p>```typescript
// Line 258-259: Vulnerable regex with nested quantifiers
const p =
  /&lt;(a|link)((\s+[a-z][a-z:_-]*=("[^"]*"|'[^']*'|[^\s&gt;]+))+)\s*\/?&gt;/ig;</p>
<p>// Line 261: No size limit on response body
const html = await response.text();</p>
<p>// Line 264: Regex execution loop
while ((m = p.exec(html)) !== null) rawAttribs.push(m[2]);
```</p>
<p>### Root Cause Analysis</p>
<p>The regex has **nested quantifiers with alternation**, which is a classic ReDoS pattern:</p>
<p>```
/&lt;(a|link)((\s+…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rchf-xwx2-hm93"/>
  </entry>
</feed>
