Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34148

26
FAUCET Score

OVERVIEW CVE-2026-34148 affects Fedify, a TypeScript library used to build federated server applications powered by ActivityPub. The vulnerability exists in versions prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1 and stems from improper handling of HTTP redirects in the remote and authenticated document loaders. The flaw allows attackers to exploit redirect chains without limits, forcing targeted servers to generate multiple outbound requests from a single inbound request. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, making exploitation straightforward for threat actors. The primary impact is availability, as attackers can trigger resource exhaustion and denial of service conditions by forcing recursive redirect loops through malicious ActivityPub keys or actor URLs they control. EXPLOITATION STATUS There is no indication of active exploitation in the wild at this time. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and maintains an inactive status on threat tracking platforms. The extremely low EPSS score of 0.00058 suggests minimal real-world exploitation likelihood. Patch availability across multiple version branches provides a clear remediation path for affected organizations.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9.6CPE matchmatch criteria
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:*
>= 1.10.0, < 1.10.5CPE matchmatch criteria
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:*
>= 2.0.0, < 2.0.8CPE matchmatch criteria
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:*
>= 2.1.0, < 2.1.1CPE matchmatch criteria
cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:*
< 2.0.8CPE matchmatch criteria
cpe:2.3:a:fedify:fedify\/vocab-runtime:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 20th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

npmpatch availablevia ghsa
Product: @fedify/fedifyFixed in: 1.9.6
npmpatch availablevia ghsa
Product: @fedify/vocab-runtimeFixed in: 2.0.8
npmpatch availablevia ghsa
Product: @fedify/vocab-runtimeFixed in: 2.1.1
npmpatch availablevia ghsa
Product: @fedify/fedifyFixed in: 1.10.5
npmpatch availablevia ghsa
Product: @fedify/fedifyFixed in: 2.0.8
npmpatch availablevia ghsa
Product: @fedify/fedifyFixed in: 2.1.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-gm9m-gwc4-hwgphigh

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

Apr 7, 2026

References

github.com / fedify-dev/fedify/releases/tag/1.10.5
Release Notes
github.com / fedify-dev/fedify/releases/tag/1.9.6
Release Notes
github.com / fedify-dev/fedify/releases/tag/2.0.8
Release Notes
github.com / fedify-dev/fedify/releases/tag/2.1.1
Release Notes
github.com / fedify-dev/fedify/security/advisories/GHSA-gm9m-gwc4-hwgp
ExploitVendor Advisory