VYPR

Lemmy

by LemmyNet

Source repositories

CVEs (9)

  • CVE-2026-29178HigMar 6, 2026
    risk 0.43cvss —epss 0.00

    Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to…

  • CVE-2024-23649HigJan 24, 2024
    risk 0.42cvss 7.5epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating a private message report contains the…

  • CVE-2026-54739MedAug 19, 2026
    risk 0.38cvss —epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/login.rs returns different errors depending on whether the username_or_email value exists. LocalUserView::find_by_email_or_name…

  • CVE-2026-54743MedAug 19, 2026
    risk 0.35cvss —epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html…

  • CVE-2026-54740MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moderator can remove a higher-ranked moderator by sending a signed ActivityPub Remove activity to the target instance. The local API uses…

  • CVE-2026-54738MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled…

  • CVE-2026-54741MedAug 19, 2026
    risk 0.27cvss —epss 0.00

    Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private messages from a sender after the recipient blocks that sender, but the edit path skips the same block check. create_private_message checks the recipient's block…

  • CVE-2026-54742MedAug 19, 2026
    risk 0.26cvss —epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After…

  • CVE-2025-25194MedFeb 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of…