Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
- Severity:
- High
Description
@fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.
Recommendation
Update the @fedify/vocab-runtime package to the latest compatible version. Followings are version details:
Affected version(s): **= 2.1.0 < 2.0.8** Patched version(s): **2.1.1 2.0.8**
References
Related Issues
- seroval Affected by Remote Code Execution via JSON Deserialization - CVE-2026-23737
- Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges - CVE-2026-50131
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas - CVE-2026-41138
You might also like:
- Tags:
- npm
- @fedify/vocab-runtime
Anything's wrong? Let us know Last updated on June 09, 2026


