Fedify is a small-scale ActivityPub library and related ecosystem project centered on federated social-media implementation, with observed vulnerabilities spanning the core library, vocabulary runtime, and dependent projects such as Hollo. The exposure clusters around resource-management and authorization weaknesses—including unthrottled resource allocation, inefficient regular-expression matching, missing authorization checks, and uncontrolled consumption patterns—that are characteristic of protocol-parsing and identity-verification logic in decentralized systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fedify over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34148HIGH Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursivel | Apr 6, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-68475HIGH Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Servic | Dec 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2026-25808HIGH Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and fol | Feb 9, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fedify.
Media articles that mention a CVE ID that affects a product developed by Fedify — matched by CVE ID, not by vendor name.