Vulnerability library
Security checkJuly 14, 2026

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the current IPv4 validation logic appears incomplete.

The validatePublicUrl() protection relies on isValidPublicIPv4Address() to reject non-public IPv4 destinations.

Recommendation

Update the @fedify/vocab-runtime package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 2.2.0, < 2.2.4 >= 2.1.0, < 2.1.15 < 2.0.19**
  • Patched version(s): **2.2.4 2.1.15 2.0.19**

References

Could your website be exposed too?

SmartScanner can check your website for Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 14, 2026