OVERVIEW CVE-2026-34148 affects Fedify, a TypeScript library used to build federated server applications powered by ActivityPub. The vulnerability exists in versions prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1 and stems from improper handling of HTTP redirects in the remote and authenticated document loaders. The flaw allows attackers to exploit redirect chains without limits, forcing targeted servers to generate multiple outbound requests from a single inbound request. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, making exploitation straightforward for threat actors. The primary impact is availability, as attackers can trigger resource exhaustion and denial of service conditions by forcing recursive redirect loops through malicious ActivityPub keys or actor URLs they control. EXPLOITATION STATUS There is no indication of active exploitation in the wild at this time. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and maintains an inactive status on threat tracking platforms. The extremely low EPSS score of 0.00058 suggests minimal real-world exploitation likelihood. Patch availability across multiple version branches provides a clear remediation path for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.6CPE matchmatch criteria | cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* | ||
>= 1.10.0, < 1.10.5CPE matchmatch criteria | cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.0.8CPE matchmatch criteria | cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* | ||
>= 2.1.0, < 2.1.1CPE matchmatch criteria | cpe:2.3:a:fedify:fedify\/fedify:*:*:*:*:*:node.js:*:* | ||
< 2.0.8CPE matchmatch criteria | cpe:2.3:a:fedify:fedify\/vocab-runtime:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.