Executive brief
Fedify, a library for building decentralized social media applications, contains a flaw in how it validates web addresses. While it attempts to block access to private internal networks, it fails to recognize several special-use and reserved address ranges as restricted. An attacker could exploit this to force the server to send requests to internal or sensitive network locations, potentially leading to unauthorized data access or service disruption.
Technical details
The vulnerability exists in the `isValidPublicIPv4Address` function within `packages/vocab-runtime/src/url.ts`. While the function implements a denylist for common private ranges (like 10.0.0.0/8 and 192.168.0.0/16), it fails to account for other non-public ranges including Carrier-grade NAT (100.64.0.0/10), Benchmarking (198.18.0.0/15), Multicast (224.0.0.0/4), and IETF protocol assignments (192.0.0.0/24). An attacker can provide a specially crafted ActivityPub object or media URL pointing to these ranges to bypass SSRF protections. The issue is fixed in versions 1.9.12, 1.10.11, 2.0.19, 2.1.15, and 2.2.4 by expanding the validation logic to cover all IANA special-use IPv4 ranges.
Affected products
- fedify-dev fedify >= 0.11.2, < 1.9.12; >= 1.10.0, < 1.10.11; >= 2.0.0, < 2.0.19; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.4
- fedify-dev vocab-runtime < 2.0.19; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.4
Timeline
- 2026-06-08: advisory: Initial advisory published
- 2026-07-14: advisory: Advisory updated
References
- https://api.github.com/users/chaitanyagarware
- https://github.com/chaitanyagarware
- https://api.github.com/users/chaitanyagarware/gists%7B/gist_id%7D
- https://api.github.com/users/chaitanyagarware/repos
- https://avatars.githubusercontent.com/u/97582002?v=4
- https://api.github.com/users/chaitanyagarware/events%7B/privacy%7D