Fedify: an ActivityPub server framework<p>We released <a class="mention hashtag" rel="nofollow noopener noreferrer" href="https://hollo.social/tags/Fedify" target="_blank">#<span>Fedify</span></a> <a href="https://github.com/dahlia/fedify/releases/tag/0.9.2" rel="nofollow noopener noreferrer" target="_blank">0.9.2</a>, <a href="https://github.com/dahlia/fedify/releases/tag/0.10.1" rel="nofollow noopener noreferrer" target="_blank">0.10.1</a>, and <a href="https://github.com/dahlia/fedify/releases/tag/0.11.1" rel="nofollow noopener noreferrer" target="_blank">0.11.1</a>, which patched the last reported <a class="mention hashtag" rel="nofollow noopener noreferrer" href="https://hollo.social/tags/vulnerability" target="_blank">#<span>vulnerability</span></a>, <a href="https://github.com/dahlia/fedify/security/advisories/GHSA-p9cg-vqcc-grcx" rel="nofollow noopener noreferrer" target="_blank">CVE-2024-39687</a>, but the vulnerability of <a href="https://owasp.org/www-community/attacks/Server_Side_Request_Forgery" rel="nofollow noopener noreferrer" target="_blank">SSRF</a> attacks via DNS rebinding still exists, so we released Fedify <a href="https://github.com/dahlia/fedify/releases/tag/0.9.3" rel="nofollow noopener noreferrer" target="_blank">0.9.3</a>, <a href="https://github.com/dahlia/fedify/releases/tag/0.10.2" rel="nofollow noopener noreferrer" target="_blank">0.10.2</a>, and <a href="https://github.com/dahlia/fedify/releases/tag/0.11.2" rel="nofollow noopener noreferrer" target="_blank">0.11.2</a>, which fixes it.</p>
<p>If you are using an earlier version, please update as soon as possible.</p>
<p>Thanks to <a translate="no" class="h-card u-url mention" href="https://catcatnya.com/@benaryorg" rel="nofollow noopener noreferrer" target="_blank">@<span>benaryorg</span></a> for reporting the vulnerability!</p>
<p><a class="mention hashtag" rel="nofollow noopener noreferrer" href="https://hollo.social/tags/SSRF" target="_blank">#<span>SSRF</span></a> <a class="mention hashtag" rel="nofollow noopener noreferrer" href="https://hollo.social/tags/security" target="_blank">#<span>security</span></a> <a class="mention hashtag" rel="nofollow noopener noreferrer" href="https://hollo.social/tags/fedidev" target="_blank">#<span>fedidev</span></a></p>