Ad

CVE-2025-23221

MEDIUM CVSS 3.1: 5.4 EPSS 0.11%
Updated Jan 20, 2025
Fedify
Parameter Value
CVSS 5.4 (MEDIUM)
Fixed In 1.0.14
Type CWE-835, CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Fedify
Public PoC No

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to maneuver the Webfinger mechanism to perform a GET request to any internal resource on any Host, Port, URL combination regardless of present security mechanisms, and forcing the victim’s server into an infinite loop causing Denial of Service. Moreover, this issue can also be maneuvered into performing a Blind SSRF attack.

This vulnerability is fixed in 1.0.14, 1.1.11, 1.2.11, and 1.3.4.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Related Vulnerabilities