
🌐 ActivityPub library Fedify hit by SSRF CVE-2026-62857 Fedify's getNodeInfo() can follow attacker-controlled URLs without properly restricting schemes, redirects or private addresses. Potential targets include localhost, private networks and cloud metadata services. 🔎 Source: Tenable / GitHub Advisory #SSRF #ActivityPub #CloudSecurity #CVE
Post summary
The tweet discloses a new SSRF vulnerability (CVE-2026-62857) in the Fedify ActivityPub library that allows attackers to resolve arbitrary URLs, potentially targeting localhost, private networks, and cloud metadata services.
