CVE-2026-71246: Pixelfed
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking the resolved IP against private, internal, or link-local ranges (e.g. 169.254.169.254).
Affected products
- Pixelfed Pixelfed: version 0 only
Published 2026-08-05. Last modified 2026-08-26.