PT-2025-52723 · Fedify · Fedify

Yueyuel

·

Published

2025-12-22

·

Updated

2025-12-26

·

CVE-2025-68475

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fedify versions prior to 1.6.13 Fedify versions prior to 1.7.14 Fedify versions prior to 1.8.15 Fedify versions prior to 1.9.2
Description Fedify is a TypeScript library used for building federated server applications based on ActivityPub. A Regular Expression Denial of Service (ReDoS) issue exists in the document loader component. The HTML parsing regular expression located at packages/fedify/src/runtime/docloader.ts:259 includes nested quantifiers that can lead to catastrophic backtracking when processing specially crafted HTML responses. This can cause a denial of service.
Recommendations Update to Fedify version 1.6.13 or later. Update to Fedify version 1.7.14 or later. Update to Fedify version 1.8.15 or later. Update to Fedify version 1.9.2 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-68475
GHSA-RCHF-XWX2-HM93

Affected Products

Fedify