Server-Side Request Forgery in Fedify TypeScript Library
CVE-2026-62857
8.8HIGH
What is CVE-2026-62857?
The Fedify TypeScript library versions 1.2.0 through 2.3 contain a vulnerability where the getNodeInfo() function improperly processes attacker-controlled links, specifically from /.well-known/nodeinfo without proper validation. This flaw allows an attacker to initiate requests to internal services that should be protected, including loopback, link-local, cloud metadata, and private network services, potentially exposing sensitive information. The vulnerability has been addressed in the releases 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.
Affected Version(s)
fedify >= 1.2.0, < 1.9.13 < 1.2.0, 1.9.13
fedify >= 1.10.0, < 1.10.12 < 1.10.0, 1.10.12
fedify >= 2.0.0, < 2.0.22 < 2.0.0, 2.0.22
