CVE-2025-68475: Fedify
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.
Affected products
- Fedify Fedify: before 1.6.13 (fixed in 1.6.13); from 1.7.0, before 1.7.14 (fixed in 1.7.14); from 1.8.1, before 1.8.15 (fixed in 1.8.15); from 1.9.0, before 1.9.2 (fixed in 1.9.2)
Published 2025-12-22. Last modified 2026-09-28.