PT-2026-30656 · Fedify · Fedify

·

CVE-2026-34148

·

Published

2026-04-06

·

Updated

2026-06-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Fedify versions prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1
Description: Fedify does not enforce a maximum redirect count or visited-URL loop detection when following HTTP redirects in its remote and authenticated document loaders. An attacker controlling a remote ActivityPub key or actor URL can exploit this to force the server to make repeated outbound requests from a single inbound request, leading to resource consumption and denial of service. The issue occurs because the document loader recursively follows 3xx responses without a redirect cap or loop detection. Failed key fetches are not durably negatively cached, allowing repeated exploitation. A proof-of-concept demonstrates that a single request can trigger hundreds of outbound requests via self-redirects.
Recommendations: Upgrade to Fedify version 1.9.6, 1.10.5, 2.0.8, or 2.1.1.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34148
GHSA-GM9M-GWC4-HWGP

Affected Products

Fedify