GHSA-xw9q-2mv6-9fr8
HIGHCVE-2026-50131Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the current IPv4 validation logic appears incomplete.
- Affected
- >= 0.11.2, < 1.9.12
- Fixed in
- 1.9.12
- Weakness
- CWE-918
- Published
- 2026-07-14
- Source
- github