CVE-2026-71246
EUVD-2026-5331905.08.2026, 11:16
Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking the resolved IP against private, internal, or link-local ranges (e.g. 169.254.169.254).
Awaiting analysis
This vulnerability is currently awaiting analysis.
References