<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:10:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264271</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264271</link>
      <description>EUVD-2026-264271</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264271</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68475</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68475</link>
      <description>&lt;p&gt;Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify&amp;#39;s document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify&amp;#39;s document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68475</guid>
    </item>
    <item>
      <title>GHSA-rchf-xwx2-hm93 — Fedify has ReDoS Vulnerability in HTML Parsing Regex</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rchf-xwx2-hm93</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fedify/fedify&lt;/p&gt;
&lt;p&gt;Hi Fedify team! 👋&lt;/p&gt;
&lt;p&gt;Thank you for your work on Fedify—it&amp;#39;s a fantastic library for building federated applications. While reviewing the codebase, I discovered a Regular Expression Denial of Service (ReDoS) vulnerability that I&amp;#39;d like to report. I hope this helps improve the project&amp;#39;s security.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify&amp;#39;s document loader. The HTML parsing regex at `packages/fedify/src/runtime/docloader.ts:259` contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses.&lt;/p&gt;
&lt;p&gt;**An attacker-controlled federated server can respond with a small (~170 bytes) malicious HTML payload that blocks the victim&amp;#39;s Node.js event loop for 14+ seconds, causing a Denial of Service.**&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **CWE** | CWE-1333 (Inefficient Regular Expression Complexity) |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;The vulnerability is located in `packages/fedify/src/runtime/docloader.ts`, lines 258-264:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 258-259: Vulnerable regex with nested quantifiers
const p =
  /&amp;lt;(a|link)((\s+[a-z][a-z:_-]*=(&amp;#34;[^&amp;#34;]*&amp;#34;|&amp;#39;[^&amp;#39;]*&amp;#39;|[^\s&amp;gt;]+))+)\s*\/?&amp;gt;/ig;&lt;/p&gt;
&lt;p&gt;// Line 261: No size limit on response body
const html = await response.text();&lt;/p&gt;
&lt;p&gt;// Line 264: Regex execution loop
while ((m = p.exec(html)) !== null) rawAttribs.push(m[2]);
```&lt;/p&gt;
&lt;p&gt;### Root Cause Analysis&lt;/p&gt;
&lt;p&gt;The regex has **nested quantifiers with alternation**, which is a classic ReDoS pattern:&lt;/p&gt;
&lt;p&gt;```
/&amp;lt;(a|link)((\s+…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fedify/fedify&lt;/p&gt;
&lt;p&gt;Hi Fedify team! 👋&lt;/p&gt;
&lt;p&gt;Thank you for your work on Fedify—it&amp;#39;s a fantastic library for building federated applications. While reviewing the codebase, I discovered a Regular Expression Denial of Service (ReDoS) vulnerability that I&amp;#39;d like to report. I hope this helps improve the project&amp;#39;s security.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify&amp;#39;s document loader. The HTML parsing regex at `packages/fedify/src/runtime/docloader.ts:259` contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses.&lt;/p&gt;
&lt;p&gt;**An attacker-controlled federated server can respond with a small (~170 bytes) malicious HTML payload that blocks the victim&amp;#39;s Node.js event loop for 14+ seconds, causing a Denial of Service.**&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **CWE** | CWE-1333 (Inefficient Regular Expression Complexity) |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;The vulnerability is located in `packages/fedify/src/runtime/docloader.ts`, lines 258-264:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 258-259: Vulnerable regex with nested quantifiers
const p =
  /&amp;lt;(a|link)((\s+[a-z][a-z:_-]*=(&amp;#34;[^&amp;#34;]*&amp;#34;|&amp;#39;[^&amp;#39;]*&amp;#39;|[^\s&amp;gt;]+))+)\s*\/?&amp;gt;/ig;&lt;/p&gt;
&lt;p&gt;// Line 261: No size limit on response body
const html = await response.text();&lt;/p&gt;
&lt;p&gt;// Line 264: Regex execution loop
while ((m = p.exec(html)) !== null) rawAttribs.push(m[2]);
```&lt;/p&gt;
&lt;p&gt;### Root Cause Analysis&lt;/p&gt;
&lt;p&gt;The regex has **nested quantifiers with alternation**, which is a classic ReDoS pattern:&lt;/p&gt;
&lt;p&gt;```
/&amp;lt;(a|link)((\s+…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rchf-xwx2-hm93</guid>
    </item>
  </channel>
</rss>
