VYPR

crates.io package

lemmy_api_common

pkg:cargo/lemmy_api_common

Vulnerabilities (2)

  • CVE-2026-42181MedMay 8, 2026
    affected < 0.19.18fixed 0.19.18

    Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the default StoreLinkPreviews image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked aga

  • CVE-2026-42180MedMay 8, 2026
    affected < 0.19.18fixed 0.19.18

    Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link post through POST /api/v3/post. When a post is created in a public community, the backend asynchronously sends a Webmention to the