Junglewise Threat Intelligence

CVE-2025-68475: Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.

CVE-2025-68475 · Severity: high · CVSS 7.5 · Published 2025-12-22

Technologies: Fedify. Vendors: Fedify.

Executive brief

Fedify is a TypeScript library for building federated applications that follow ActivityPub standards. The library contains a regular expression denial of service (ReDoS) vulnerability in its HTML parser that can be triggered when fetching actor profiles from untrusted federated servers. An attacker can serve a small, specially crafted HTML response (~170 bytes) that causes Fedify's Node.js event loop to block for 14+ seconds, effectively disabling the service and preventing legitimate requests from being processed.

Technical details

The vulnerability exists in packages/fedify/src/runtime/docloader.ts:259, where a regular expression with nested quantifiers and alternation is used to parse HTML attributes: `/<(a|link)((\s+[a-z][a-z:_-]*=("[^"]*"|'[^']*'|[^\s>]+))+)\s*\/?>/ig`. The nested quantifier pattern (`((...)+)+`) combined with alternation creates exponential backtracking when the regex engine fails to match incomplete HTML tags. The vulnerability is remotely exploitable without authentication because Fedify fetches profiles from untrusted federated servers, and there are no response size limits or default timeouts enforced. An attacker can block the event loop by sending a malicious payload, causing a denial of service that degrades or disables the application. Patched versions (1.6.13, 1.7.14, 1.8.15, 1.9.2) are available.

Affected products

  • Fedify Fedify <=1.9.1

Timeline

  • 2025-12-22: disclosed: Vulnerability published via GHSA-rchf-xwx2-hm93
  • 2025-12-22: patched: Patched versions 1.6.13, 1.7.14, 1.8.15, 1.9.2 released

References

Related threats