<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:58:17.830560+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281036</id>
    <title>EUVD-2026-281036</title>
    <updated>2026-10-05T21:58:17.876930+00:00</updated>
    <content>EUVD-2026-281036</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34148</id>
    <title>fkie_cve-2026-34148</title>
    <updated>2026-10-05T21:58:17.876965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. This vulnerability is fixed in 1.9.6, 1.10.5, 2.0.8, and 2.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gm9m-gwc4-hwgp</id>
    <title>GHSA-gm9m-gwc4-hwgp — Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution</title>
    <updated>2026-10-05T21:58:17.876998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @fedify/fedify, npm: @fedify/vocab-runtime</p>
<p>### Summary</p>
<p>`@fedify/fedify` follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection. An attacker who controls a remote ActivityPub key or actor URL can force a server using Fedify to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service.</p>
<p>### Details</p>
<p>Fedify verifies ActivityPub HTTP signatures by fetching the remote `keyId` during request processing. The relevant flow is `handleInboxInternal()` -&gt; `verifyRequest()` -&gt; `fetchKeyInternal()` -&gt; document loader.</p>
<p>In affected versions:
- the generic document loader recursively follows `3xx` responses by calling `load()` again on the `Location` header
- the authenticated redirect path (`doubleKnock()`) also recursively follows redirects
- neither path enforces a redirect cap or tracks visited URLs to detect self-referential redirect loops</p>
<p>As a result, if an attacker-controlled `keyId` or actor URL responds with `302 Location: &lt;same URL&gt;`, a single ActivityPub request can trigger tens or hundreds of outbound requests before the fetch completes or the request times out.</p>
<p>I confirmed the issue in `@fedify/fedify` 1.9.1 and 1.9.2. By contrast, Fedify's WebFinger lookup path already has a redirect cap, which suggests the missing bound in the document loader is unintended.</p>
<p>Failed key fetches are not durably negatively cached. After a failed lookup, the nul…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gm9m-gwc4-hwgp"/>
  </entry>
</feed>
