Fedify Webfinger Mechanism Vulnerability Leading to Denial-of-Service and Blind Server-Side Request Forgery

Vulnerability

A vulnerability in the Fedify TypeScript library allows manipulation of the Webfinger mechanism to send GET requests to any internal resource on any host, port, or URL, bypassing existing security measures. This exploitation forces the victim's server into an infinite loop, causing a denial-of-service condition. Additionally, the vulnerability can be exploited to perform a blind server-side request forgery attack. The issue arises in versions 1.0.13, 1.1.10, 1.2.10, and 1.3.3, and has been patched in 1.0.14, 1.1.11, 1.2.11, and 1.3.4.

Impact

Exploitation of this vulnerability leads to an infinite loop on the server, causing a denial-of-service condition. It also allows for blind server-side request forgery, where the server is tricked into making requests to internal resources or external services without the user's knowledge.

Reproduction

The vulnerability can be reproduced by creating a federated application that includes a malicious actor object. This object should contain an actor ID URL pointing to a server that performs recursive redirects to itself, creating an infinite loop. Alternatively, the actor ID can point to an internal resource, leveraging the blind SSRF aspect of the vulnerability.

Remediation

Users can update to Fedify versions 1.0.14, 1.1.11, 1.2.11, or 1.3.4 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.8
exploitability
8.4
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.