---
id: CVE-2025-68475
title: >-
  Fedify is a TypeScript library for building federated server apps powered by
  ActivityPub
summary: >-
  Fedify is a TypeScript library for building federated server apps powered by
  ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular
  Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document
  loade…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
vendor: fedify
product: fedify
affected:
  - fedify < 1.6.13
  - 'fedify >= 1.7.0, < 1.7.14'
  - 'fedify >= 1.8.1, < 1.8.15'
  - 'fedify >= 1.9.0, < 1.9.2'
patched:
  - fedify 1.9.2
published: '2025-12-22'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T10:10:00.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68475'
references:
  - url: >-
      https://github.com/fedify-dev/fedify/commit/2bdcb24d7d6d5886e0214ed504b63a6dc5488779
    label: security-advisories@github.com
  - url: >-
      https://github.com/fedify-dev/fedify/commit/bf2f0783634efed2663d1b187dc55461ee1f987a
    label: security-advisories@github.com
  - url: 'https://github.com/fedify-dev/fedify/releases/tag/1.6.13'
    label: security-advisories@github.com
  - url: 'https://github.com/fedify-dev/fedify/releases/tag/1.7.14'
    label: security-advisories@github.com
  - url: 'https://github.com/fedify-dev/fedify/releases/tag/1.8.15'
    label: security-advisories@github.com
  - url: 'https://github.com/fedify-dev/fedify/releases/tag/1.9.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/fedify-dev/fedify/security/advisories/GHSA-rchf-xwx2-hm93
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00559
epssPercentile: 0.44358
ingestedAt: '2026-09-28T11:08:06.667Z'
---

## Overview

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.

## Affected

- `fedify < 1.6.13`
- `fedify >= 1.7.0, < 1.7.14`
- `fedify >= 1.8.1, < 1.8.15`
- `fedify >= 1.9.0, < 1.9.2`

## Remediation

Upgrade past the affected range:

- `fedify 1.9.2`
