<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:00:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326605</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326605</link>
      <description>EUVD-2026-326605</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326605</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42462</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42462</link>
      <description>&lt;p&gt;Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42462</guid>
    </item>
    <item>
      <title>GHSA-9rfg-v8g9-9367 — Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9rfg-v8g9-9367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fedify/fedify&lt;/p&gt;
&lt;p&gt;As told on Discord earlier, multiple projects are affected, and we would like to coordinate. For now, we are aiming at a May 6th release date, but this is not set in stone yet.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability essentially boils down to the signature being on the canonical RDF graph representation of the JSON-LD document, and JSON-LD offering many ways to represent the same graph.&lt;/p&gt;
&lt;p&gt;One of the issues is that by taking a signed `Activity` with an embedded `object`, an attacker can move the top-level `Activity` to a `@graph` property and move the activity&amp;#39;s `object` to the top-level. Such a transformation preserves the signature and changes how the payload is interpreted by pretty much all ActivityPub implementations, making them process the object and ignore the formely-top-level activity. This can be used when the graph contains an embedded activity. In Mastodon, that is the case of `{ &amp;#34;type&amp;#34;: &amp;#34;Undo&amp;#34;, &amp;#34;object&amp;#34;: { &amp;#34;type&amp;#34;: &amp;#34;Announce&amp;#34; } }`, but other implementations may sign other activities that can be exploited in the same way.&lt;/p&gt;
&lt;p&gt;The `@reverse` keyword can also be used to change the shape of a JSON-LD document without changing the underlying graph, and could be used in a similar way to reverse an `Activity` and its `object`.&lt;/p&gt;
&lt;p&gt;Anoth…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fedify/fedify&lt;/p&gt;
&lt;p&gt;As told on Discord earlier, multiple projects are affected, and we would like to coordinate. For now, we are aiming at a May 6th release date, but this is not set in stone yet.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability essentially boils down to the signature being on the canonical RDF graph representation of the JSON-LD document, and JSON-LD offering many ways to represent the same graph.&lt;/p&gt;
&lt;p&gt;One of the issues is that by taking a signed `Activity` with an embedded `object`, an attacker can move the top-level `Activity` to a `@graph` property and move the activity&amp;#39;s `object` to the top-level. Such a transformation preserves the signature and changes how the payload is interpreted by pretty much all ActivityPub implementations, making them process the object and ignore the formely-top-level activity. This can be used when the graph contains an embedded activity. In Mastodon, that is the case of `{ &amp;#34;type&amp;#34;: &amp;#34;Undo&amp;#34;, &amp;#34;object&amp;#34;: { &amp;#34;type&amp;#34;: &amp;#34;Announce&amp;#34; } }`, but other implementations may sign other activities that can be exploited in the same way.&lt;/p&gt;
&lt;p&gt;The `@reverse` keyword can also be used to change the shape of a JSON-LD document without changing the underlying graph, and could be used in a similar way to reverse an `Activity` and its `object`.&lt;/p&gt;
&lt;p&gt;Anoth…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9rfg-v8g9-9367</guid>
    </item>
  </channel>
</rss>
