Vulnerabilities/

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

Severity:
High

Description

@fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.

Recommendation

Update the @fedify/vocab-runtime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@fedify/vocab-runtime
Anything's wrong? Let us know Last updated on June 09, 2026