Skip to content

Releases: fedify-dev/fedify

Fedify 2.2.4

Choose a tag to compare

@github-actions github-actions released this 04 Jun 05:59
2.2.4
e6fe71d

Released on June 4, 2026.

@fedify/vocab-runtime

  • Fixed validatePublicUrl() allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131]

  • Fixed validatePublicUrl() allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]

Fedify 2.1.15

Choose a tag to compare

@github-actions github-actions released this 04 Jun 05:50
2.1.15
2e1122e

Released on June 4, 2026.

@fedify/vocab-runtime

  • Fixed validatePublicUrl() allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131]

  • Fixed validatePublicUrl() allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]

Fedify 2.0.19

Choose a tag to compare

@github-actions github-actions released this 04 Jun 04:57
2.0.19
0bdad17

Released on June 4, 2026.

@fedify/vocab-runtime

  • Fixed validatePublicUrl() allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131]

  • Fixed validatePublicUrl() allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]

Fedify 1.10.11

Choose a tag to compare

@github-actions github-actions released this 04 Jun 04:42
1.10.11
8eb4ed1

Released on June 4, 2026.

@fedify/fedify

  • Fixed validatePublicUrl() allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131]

  • Fixed validatePublicUrl() allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]

Fedify 1.9.12

Choose a tag to compare

@github-actions github-actions released this 04 Jun 04:36
1.9.12
5b2f65e

Released on June 4, 2026.

@fedify/fedify

  • Fixed validatePublicUrl() allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131]

  • Fixed validatePublicUrl() allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]

Fedify 2.2.3

Choose a tag to compare

@github-actions github-actions released this 20 May 17:21
2.2.3
8140088

Released on May 21, 2026.

@fedify/fedify

  • Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]

Fedify 2.1.14

Choose a tag to compare

@github-actions github-actions released this 20 May 17:05
2.1.14
5a5802e

Released on May 21, 2026.

@fedify/fedify

  • Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]

Fedify 2.0.18

Choose a tag to compare

@github-actions github-actions released this 20 May 16:45
2.0.18
2af7014

Released on May 21, 2026.

@fedify/fedify

  • Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]

Fedify 1.10.10

Choose a tag to compare

@github-actions github-actions released this 20 May 16:17
1.10.10
5e2cf79

Released on May 21, 2026.

@fedify/fedify

  • Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]

Fedify 1.9.11

Choose a tag to compare

@github-actions github-actions released this 20 May 16:13
1.9.11
d61de18

Released on May 21, 2026.

@fedify/fedify

  • Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]