Security: LemmyNet/lemmy
Security
.github/SECURITY.md
-
SSRF in /api/v3/post via Webmention dispatchGHSA-3jvj-v6w2-h948 published
Apr 20, 2026 by NutomicModerate -
SSRF and internal image disclosure in post link metadata via unvalidated og:imageGHSA-h6hf-9846-xwrq published
Apr 20, 2026 by NutomicModerate -
Blind SSRF in /api/v3/resolve_object, normal user can reach internal services and make outbound requestsGHSA-c482-7gjx-pp36 published
Apr 13, 2026 by NutomicLow -
SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()GHSA-q537-8fr5-cw35 published
Mar 23, 2026 by NutomicModerate -
Unauthenticated SSRF via file_type query parameter injection in image endpointGHSA-jvxv-2jjp-jxc3 published
Mar 3, 2026 by NutomicModerate -
DB performance issuesGHSA-x57w-mr53-3f5h published
Jun 24, 2025 by NutomicLow -
Local users can delete arbitrary entries from the local_image tableGHSA-373q-r73m-8mrg published
Jun 19, 2025 by NutomicModerate -
Local users can delete arbitrary pict-rs mediaGHSA-7xwp-jqhc-v6vw published
Jun 19, 2025 by NutomicModerate -
Purging users or communities or banning users can delete images they didn't upload/exclusively useGHSA-wr2m-38xh-rpc9 published
Apr 8, 2025 by dessalinesModerate -
Server-Side Request Forgery (SSRF) in activitypub_federationGHSA-7723-35v7-qcxw published
Feb 10, 2025 by dessalinesModerate
Learn more about advisories related to LemmyNet/lemmy in the GitHub Advisory Database