{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-24T14:14:28.995","vulnerabilities":[{"cve":{"id":"CVE-2026-29178","sourceIdentifier":"security-advisories@github.com","published":"2026-03-06T18:16:20.650","lastModified":"2026-06-17T10:29:43.650","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter injection in the file_type query parameter. An attacker can inject arbitrary query parameters into the internal request to pict-rs, including the proxy parameter which causes pict-rs to fetch arbitrary URLs. This issue has been patched in version 0.19.16."},{"lang":"es","value":"Lemmy, un agregador de enlaces y foro para el fediverso, es vulnerable a la falsificación de petición del lado del servidor a través de una dependencia de activitypub_federation, un framework para la federación de ActivityPub en Rust. Antes de la versión 0.19.16, el endpoint GET /API/v4/image/{filename} es vulnerable a SSRF no autenticado a través de la inyección de parámetros en el parámetro de consulta file_type. Un atacante puede inyectar parámetros de consulta arbitrarios en la petición interna a pict-rs, incluyendo el parámetro proxy que hace que pict-rs obtenga URLs arbitrarias. Este problema ha sido parcheado en la versión 0.19.16."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"LemmyNet","product":"lemmy","versions":[{"version":"< 0.19.16","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-06T18:33:04.955735Z","id":"CVE-2026-29178","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/LemmyNet/lemmy/commit/f47a03f56d1797bceab5f34b6f624c91cecd5871","source":"security-advisories@github.com"},{"url":"https://github.com/LemmyNet/lemmy/security/advisories/GHSA-jvxv-2jjp-jxc3","source":"security-advisories@github.com"},{"url":"https://github.com/LemmyNet/lemmy/security/advisories/GHSA-jvxv-2jjp-jxc3","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}}]}