Fedify security updates: 1.0.14, 1.1.11, 1.2.11, and 1.3.4 #200
dahlia
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We have released security updates (1.0.14, 1.1.11, 1.2.11, 1.3.4) to address CVE-2025-23221, a vulnerability in Fedify's WebFinger implementation. We recommend all users update to the latest version of their respective release series immediately.
The Vulnerability
A security researcher identified multiple security issues in Fedify's
lookupWebFinger()
function that could be exploited to:Fixed Versions
Changes
The security updates implement the following fixes:
How to Update
To update to the latest secure version:
We thank the security researcher who responsibly disclosed this vulnerability, allowing us to address these issues promptly.
For more details about this vulnerability, please refer to our security advisory.
If you have any questions or concerns, please don't hesitate to reach out through our GitHub Discussions, join our Matrix chat space, or our Discord server.
Beta Was this translation helpful? Give feedback.
All reactions