CVE-2026-71246: Pixelfed

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking the resolved IP against private, internal, or link-local ranges (e.g. 169.254.169.254).

Affected products

Published 2026-08-05. Last modified 2026-08-26.