{"id":"CVE-2025-68475","aliases":["GHSA-rchf-xwx2-hm93"],"url":"https://o3.security/vulnerability/CVE-2025-68475","summary":"Fedify has ReDoS Vulnerability in HTML Parsing Regex","details":"Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.","published":"2025-12-22T21:31:20.314Z","modified":"2026-08-08T03:48:16.397890457Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fedify/fedify","fixedVersion":"1.6.13"},{"ecosystem":"npm","name":"@fedify/fedify","fixedVersion":"1.7.14"},{"ecosystem":"npm","name":"@fedify/fedify","fixedVersion":"1.8.15"},{"ecosystem":"npm","name":"@fedify/fedify","fixedVersion":"1.9.2"}],"fix":{"url":"https://github.com/fedify-dev/fedify/commit/2bdcb24d7d6d5886e0214ed504b63a6dc5488779","label":"fedify-dev/fedify@2bdcb24"},"references":[{"type":"WEB","url":"https://github.com/fedify-dev/fedify/releases/tag/1.6.13"},{"type":"WEB","url":"https://github.com/fedify-dev/fedify/releases/tag/1.7.14"},{"type":"WEB","url":"https://github.com/fedify-dev/fedify/releases/tag/1.8.15"},{"type":"WEB","url":"https://github.com/fedify-dev/fedify/releases/tag/1.9.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68475.json"},{"type":"ADVISORY","url":"https://github.com/fedify-dev/fedify/security/advisories/GHSA-rchf-xwx2-hm93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68475"},{"type":"FIX","url":"https://github.com/fedify-dev/fedify/commit/2bdcb24d7d6d5886e0214ed504b63a6dc5488779"},{"type":"FIX","url":"https://github.com/fedify-dev/fedify/commit/bf2f0783634efed2663d1b187dc55461ee1f987a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:16.397890457Z"}}