CVE-2026-50131 | fedify-dev fedify/vocab-runtime prior 1.9.12/1.10.11/2.0.19/2.1.15/2.2.4 URL Validation validatePublicUrl server-side request forgery (GHSA-xw9q-2mv6-9fr8)
A vulnerability categorized as critical has been discovered in fedify-dev fedify and vocab-runtime. Affected is the function validatePublicUrl of the component URL Validation Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-50131. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More