« Volver al listado

CVE-2026-42462

Estado: AplazadaAlta (7)—

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de validación de firma en biblioteca remota (AV:N sin privilegios previos); permite manipulación de actividades firmadas por terceros mediante reestructuración JSON-LD, causando alteración de datos y potencial suplantación de identidades en sistemas federados.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42462",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42462",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T13:31:40.827057Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "fedify-dev",
          "product": "fedify",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.2.0, < 2.2.3"
            },
            {
              "status": "affected",
              "version": ">= 2.1.0, < 2.1.14"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.0.18"
            },
            {
              "status": "affected",
              "version": ">= 1.10.0, < 1.10.10"
            },
            {
              "status": "affected",
              "version": "< 1.9.11"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T22:16:57.387",
  "references": [
    {
      "url": "https://github.com/fedify-dev/fedify/releases/tag/2.2.3",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/security/advisories/GHSA-9rfg-v8g9-9367",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-180"
        },
        {
          "lang": "en",
          "value": "CWE-347"
        },
        {
          "lang": "en",
          "value": "CWE-436"
        },
        {
          "lang": "en",
          "value": "CWE-1289"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue."
    },
    {
      "lang": "es",
      "value": "Fedify es una biblioteca TypeScript para construir aplicaciones de servidor federadas impulsadas por ActivityPub. Antes de las versiones 1.9.11, 1.10.10, 2.0.18, 2.1.14 y 2.2.3, un atacante puede hacer uso de las características de JSON-LD para reestructurar un documento JSON-LD que cambiaría cómo Fedify lo interpreta sin cambiar su Firma de Datos Enlazados, permitiéndoles alterar una actividad firmada por terceros que hayan recibido. Las versiones 1.9.11, 1.10.10, 2.0.18, 2.1.14 y 2.2.3 solucionan el problema."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "sourceIdentifier": "security-advisories@github.com"
}