Releases: fedify-dev/fedify
Release list
Fedify 2.2.4
Released on June 4, 2026.
@fedify/vocab-runtime
-
Fixed
validatePublicUrl()allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131] -
Fixed
validatePublicUrl()allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]
Fedify 2.1.15
Released on June 4, 2026.
@fedify/vocab-runtime
-
Fixed
validatePublicUrl()allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131] -
Fixed
validatePublicUrl()allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]
Fedify 2.0.19
Released on June 4, 2026.
@fedify/vocab-runtime
-
Fixed
validatePublicUrl()allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131] -
Fixed
validatePublicUrl()allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]
Fedify 1.10.11
Released on June 4, 2026.
@fedify/fedify
-
Fixed
validatePublicUrl()allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131] -
Fixed
validatePublicUrl()allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]
Fedify 1.9.12
Released on June 4, 2026.
@fedify/fedify
-
Fixed
validatePublicUrl()allowing special-use IPv4 ranges, such as shared address space, benchmarking, multicast, reserved, and documentation ranges, which could bypass private network protections in remote document loading. [CVE-2026-50131] -
Fixed
validatePublicUrl()allowing IPv6 translation and tunneling prefixes, including NAT64, Teredo, and 6to4 addresses, which could bypass private network protections in remote document loading. [CVE-2026-50131]
Fedify 2.2.3
Released on May 21, 2026.
@fedify/fedify
- Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]
Fedify 2.1.14
Released on May 21, 2026.
@fedify/fedify
- Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]
Fedify 2.0.18
Released on May 21, 2026.
@fedify/fedify
- Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]
Fedify 1.10.10
Released on May 21, 2026.
@fedify/fedify
- Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]
Fedify 1.9.11
Released on May 21, 2026.
@fedify/fedify
- Fixed a security vulnerability in Linked Data Signature verification that could allow certain signed activities to be interpreted differently than intended. [CVE-2026-42462]