Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rchf-xwx2-hm93 | Fedify has ReDoS Vulnerability in HTML Parsing Regex |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2. | |
| Title | Fedify has ReDoS Vulnerability in HTML Parsing Regex | |
| Weaknesses | CWE-1333 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-22T21:54:45.635Z
Reserved: 2025-12-18T13:52:15.491Z
Link: CVE-2025-68475
Updated: 2025-12-22T21:54:41.120Z
Status : Awaiting Analysis
Published: 2025-12-22T22:16:09.143
Modified: 2025-12-23T14:51:52.650
Link: CVE-2025-68475
No data.
OpenCVE Enrichment
No data.
Github GHSA