Untriaged
Permalink
CVE-2026-33693
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
Lemmy's Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF protection introduced by the fix for CVE-2025-25194 (GHSA-7723-35v7-qcxw), and reach localhost services on the target server. Version 0.7.0-beta.9 patches the issue.
References
Affected products
lemmy
- ==< 0.7.0-beta.9
Matching in nixpkgs
pkgs.lemmy-ui
Building a federated alternative to reddit in rust
pkgs.lemmy-help
CLI for generating vim help docs from emmylua comments
Package maintainers
-
@figsoda figsoda <figsoda@pm.me>
-
@georgyo George Shammas <george@shamm.as>
-
@billewanick Bill Ewanick <bill@ewanick.com>
-
@happysalada Raphael Megzari <raphael@megzari.com>