SCA: security update for @fedify/fedify (GHSA-9rfg-v8g9-9367)

high Tenable Self-Hosted Container Security Plugin ID 443083

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to
versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to
restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data
Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11,
1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue. (CVE-2026-42462)

Solution

Update the @fedify/fedify library and its related packages to version 1.10.10 or later.

See Also

https://github.com/advisories/GHSA-9rfg-v8g9-9367

Plugin Details

Severity: High

ID: 443083

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 6/11/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.79

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:C/A:P

CVSS Score Source: CVE-2026-42462

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/26/2026

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-42462