Server-Side Request Forgery in Fedify TypeScript Library
CVE-2026-62857

8.8HIGH

Key Information:

Vendor

Fedify-dev

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-62857?

The Fedify TypeScript library versions 1.2.0 through 2.3 contain a vulnerability where the getNodeInfo() function improperly processes attacker-controlled links, specifically from /.well-known/nodeinfo without proper validation. This flaw allows an attacker to initiate requests to internal services that should be protected, including loopback, link-local, cloud metadata, and private network services, potentially exposing sensitive information. The vulnerability has been addressed in the releases 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.

Affected Version(s)

fedify >= 1.2.0, < 1.9.13 < 1.2.0, 1.9.13

fedify >= 1.10.0, < 1.10.12 < 1.10.0, 1.10.12

fedify >= 2.0.0, < 2.0.22 < 2.0.0, 2.0.22

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.