CVE-2026-62857

Source
https://cve.org/CVERecord?id=CVE-2026-62857
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62857.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-62857
Aliases
  • GHSA-hqph-j65v-8cq5
Published
2026-08-06T21:04:23.341Z
Modified
2026-08-09T03:30:37.269326677Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources
Details

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62857.json"
}
References

Affected packages

Git / github.com/fedify-dev/fedify

Affected ranges

Type
GIT
Repo
https://github.com/fedify-dev/fedify
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.2.0"
        },
        {
            "fixed": "1.9.13"
        },
        {
            "introduced": "1.10.0"
        },
        {
            "fixed": "1.10.12"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.0.22"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "fixed": "2.1.18"
        },
        {
            "introduced": "2.2.0"
        },
        {
            "fixed": "2.2.7"
        },
        {
            "introduced": "2.3.0"
        },
        {
            "fixed": "2.3.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.10.0
1.10.1
1.10.10
1.10.11
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.3.0
1.4.0
1.5.0
1.6.1
1.7.0
1.8.1
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.*
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.3.0
2.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62857.json"