Vulnerabilities/

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Severity:
High

Description

Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the current IPv4 validation logic appears incomplete.

The validatePublicUrl() protection relies on isValidPublicIPv4Address() to reject non-public IPv4 destinations.

Recommendation

Update the @fedify/vocab-runtime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@fedify/vocab-runtime
Anything's wrong? Let us know Last updated on July 14, 2026