VYPR

crates.io package

activitypub_federation

pkg:cargo/activitypub_federation

Vulnerabilities (2)

  • CVE-2026-33693MedMar 27, 2026
    affected < 0.7.0-beta.9fixed 0.7.0-beta.9

    Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain ca

  • CVE-2025-25194MedFeb 10, 2025
    affected <= 0.6.2

    Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federatio