{"id":"CVE-2026-62857","summary":"Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources","details":"Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.","aliases":["GHSA-hqph-j65v-8cq5"],"modified":"2026-08-09T03:30:37.269326677Z","published":"2026-08-06T21:04:23.341Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62857.json"},"references":[{"type":"WEB","url":"https://github.com/fedify-dev/fedify/releases/tag/2.3.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62857.json"},{"type":"ADVISORY","url":"https://github.com/fedify-dev/fedify/security/advisories/GHSA-hqph-j65v-8cq5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62857"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fedify-dev/fedify","events":[{"introduced":"2e639046343bb81f47b3f7a571aaec6812f4168e"},{"introduced":"e4277717b0cad40c6282aae3dd14d4016cda45af"},{"introduced":"9568bcde77d3f1df90e2a790f5ff81b5bc787c5d"},{"introduced":"49bfb3679ceaf3c20e4029033d19aed6f5cd9d0c"},{"introduced":"7c1bc8ab6e7f70c54fde4be3372dcd113f3f7947"},{"introduced":"f33d94c8c6e3af7a7df89c69ecc139239148adf7"},{"fixed":"6220cf8090a17051f1ac3217ed172acf8d355d87"},{"fixed":"a9fdf26105b5d3622feac42e9a1af7df875c1776"},{"fixed":"022503240e243219d940947dbb25eb6a1137c183"},{"fixed":"fb5adc324612ede97ca305eebe58743873378e84"},{"fixed":"27a189fb1db771e598cb4b91e8744f92fdbb4986"},{"fixed":"9d67b2259c8aa9293fa112e86b834e558d7fce5b"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"1.2.0"},{"fixed":"1.9.13"},{"introduced":"1.10.0"},{"fixed":"1.10.12"},{"introduced":"2.0.0"},{"fixed":"2.0.22"},{"introduced":"2.1.0"},{"fixed":"2.1.18"},{"introduced":"2.2.0"},{"fixed":"2.2.7"},{"introduced":"2.3.0"},{"fixed":"2.3.2"}]}}],"versions":["2.3.1","2.2.6","2.1.17","2.0.21","2.3.0","2.2.5","2.1.16","2.0.20","2.2.4","2.1.15","2.0.19","1.10.11","1.9.12","2.2.3","2.1.14","2.0.18","1.10.10","1.9.11","2.2.2","2.1.13","2.0.17","2.2.1","2.1.12","2.0.16","1.10.9","1.9.10","2.2.0","2.1.11","2.0.15","2.1.10","2.0.14","2.1.9","2.1.8","2.0.13","2.1.7","2.1.6","2.1.5","1.10.8","2.0.12","1.9.9","2.1.4","2.0.11","1.10.7","1.9.8","2.1.3","2.0.10","2.1.2","2.0.9","1.10.6","1.9.7","2.1.1","2.0.8","1.10.5","1.9.6","2.1.0","2.0.7","2.0.6","2.0.5","1.10.4","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.10.3","1.9.5","1.10.2","1.9.4","1.10.1","1.9.3","1.10.0","1.9.2","1.9.1","1.9.0","1.8.1","1.7.0","1.6.1","1.5.0","1.4.0","1.3.0","1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62857.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"}]}