An ActivityPub server framework
85%
Total Score
63
100
100
100
63
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10317 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @fedify/fedify is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.10.3. | 0.0.1 - 1.10.3 | Medium |
CVE-2025-68475 @fedify/fedify is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 1.6.13, 1.7.0 - 1.7.14, 1.8.0 - 1.8.15 and 1.9.0 - 1.9.2. | 0.0.0 - 1.6.131.7.0 - 1.7.141.8.0 - 1.8.15 +1 more | High |
AIKIDO-2025-10539 @fedify/fedify is vulnerable to Improper Authentication in versions 1.8.0 - 1.8.4, 1.7.0 - 1.7.8, 1.6.0 - 1.6.7, 1.5.0 - 1.5.4, 1.4.0 - 1.4.12 and 0.0.1 - 1.3.19. | 0.0.1 - 1.3.191.4.0 - 1.4.121.5.0 - 1.5.4 +3 more | High |
CVE-2025-23221 @fedify/fedify is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 1.0.13 - 1.0.13, 1.1.10 - 1.1.10, 1.2.10 - 1.2.10 and 1.3.3 - 1.3.3. | 1.0.13 - 1.0.131.1.10 - 1.1.101.2.10 - 1.2.10 +1 more | Medium |
CVE-2024-39687 @fedify/fedify is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 0.9.2, 0.10.0 - 0.10.2 and 0.11.0 - 0.11.2. | 0.0.0 - 0.9.20.10.0 - 0.10.20.11.0 - 0.11.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
jsonld Version ^9.0.0 | — | — |
es-toolkit Version 1.43.0 | — | — |
json-canon Version ^1.0.1 | — | — |
url-template Version ^3.1.1 | — | — |
@fedify/vocab Version 2.0.7 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant