An ActivityPub server framework
93%
Total Score
66
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-42462 New @fedify/fedify is vulnerable to Incorrect Behavior Order: Validate Before Canonicalize in versions 0.0.0 - 2.2.3. | 0.0.0 - 2.2.3 | High |
CVE-2026-34148 @fedify/fedify is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.9.6, 1.10.0 - 1.10.5, 2.0.0 - 2.0.8 and 2.1.0 - 2.1.0. | 0.0.0 - 1.9.61.10.0 - 1.10.52.0.0 - 2.0.8 +1 more | High |
AIKIDO-2026-10317 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @fedify/fedify is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.10.3. | 0.0.1 - 1.10.3 | Medium |
CVE-2025-68475 @fedify/fedify is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 1.6.13, 1.7.0 - 1.7.14, 1.8.0 - 1.8.15 and 1.9.0 - 1.9.2. | 0.0.0 - 1.6.131.7.0 - 1.7.141.8.0 - 1.8.15 +1 more | High |
AIKIDO-2025-10539 @fedify/fedify is vulnerable to Improper Authentication in versions 1.8.0 - 1.8.4, 1.7.0 - 1.7.8, 1.6.0 - 1.6.7, 1.5.0 - 1.5.4, 1.4.0 - 1.4.12 and 0.0.1 - 1.3.19. | 0.0.1 - 1.3.191.4.0 - 1.4.121.5.0 - 1.5.4 +3 more | High |
| Dependency | Last Release | Score |
|---|---|---|
jsonld Version ^9.0.0 | — | — |
es-toolkit Version 1.43.0 | — | — |
json-canon Version ^1.0.1 | — | — |
url-template Version ^3.1.1 | — | — |
@fedify/vocab Version 2.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant