CVE-2026-62857 | fedify-dev fedify up to 2.3.1 URL Validation getNodeInfo links[] server-side request forgery

SecurityVulns

A vulnerability categorized as critical has been discovered in fedify-dev fedify up to 2.3.1. This vulnerability affects the function getNodeInfo of the component URL Validation. Executing a manipulation of the argument links[] can lead to server-side request forgery.

The identification of this vulnerability is CVE-2026-62857. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More