CVE-2026-50131
fedify-dev fedify, vocab-runtime 취약점
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the IPv4 validation logic present starting in version 0.11.2 and prior to versions 1.9.12, 1.10.11, 2.0.19, 2.1.15, and 2.2.4 appears incomplete. The `validatePublicUrl()` protection relies on `isValidPublicIPv4Address()` to reject non-public IPv4 destinations. The function blocks common private and local ranges such as `10.0.0.0/8`, `127.0...
- 대응 우선순위
- 점검
- CVSS
- 8.6
- EPSS
- 0.35% 백분위 27.8% · 2026.07.31 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.11