Executive brief
Fedify is a TypeScript library implementing the ActivityPub protocol, which allows servers to communicate and exchange social media content. The library's WebFinger mechanism, used to resolve remote actor identities, can be exploited by an attacker to perform blind server-side request forgery (SSRF) attacks against internal resources and trigger infinite loops that cause denial of service. This could allow attackers to access internal services like localhost databases or metadata servers, or crash victim servers.
Technical details
The vulnerability exists in the lookupWebFingerInternal function, which processes actor ID URLs without proper validation of the target host and port. The function extracts the protocol and server from the actor ID and constructs a WebFinger URL, then follows HTTP 3xx redirects via custom code in a while loop without limiting the number of redirects. An attacker can craft a malicious actor ID with a redirect chain that either loops indefinitely or points to internal resources (localhost, private IPs, or arbitrary internal services). The fetch request uses "redirect: manual" but still processes Location headers, bypassing protections that would normally prevent SSRF. The vulnerability affects versions 1.0.13, 1.1.10, 1.2.10, and 1.3.3; patches are available in 1.0.14, 1.1.11, 1.2.11, and 1.3.4.
Affected products
- Fedify fedify 1.0.13, 1.1.10, 1.2.10, 1.3.3
Timeline
- 2025-01-21: disclosed
- 2025-01-20: patched: Patches released: 1.0.14, 1.1.11, 1.2.11, 1.3.4