Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LemmyNet — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting LemmyNet. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LemmyNet is a decentralized federated social network platform enabling community-driven discussions across interconnected servers. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with four CVEs documented to date. The platform's federated architecture introduces unique security considerations, though no major public incidents have been widely reported. Security researchers have identified issues related to improper input validation and insufficient access controls, particularly in API endpoints and user authentication mechanisms. The open-source nature allows for community-driven security improvements, though the complexity of federation increases potential attack surfaces across interconnected instances.

Top products by LemmyNet: lemmy
CVE ID Title CVSS Severity Published
CVE-2026-54738 Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo — lemmy CWE-799 6.5 Medium 2026-08-19
CVE-2026-54743 Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed — lemmy CWE-79 6.4 Medium 2026-08-19
CVE-2026-54739 Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential — lemmy CWE-204 6.9 Medium 2026-08-19
CVE-2026-54740 Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators — lemmy CWE-862 6.5 Medium 2026-08-19
CVE-2026-54741 Lemmy: Blocked users can edit private messages sent before the block — lemmy CWE-862 5.3 Medium 2026-08-19
CVE-2026-54742 Lemmy: `CollectionAdd::Featured` does not check the post is in the community — lemmy CWE-863 5.1 Medium 2026-08-19
CVE-2026-42180 Lemmy: SSRF in /api/v3/post via Webmention dispatch — lemmy CWE-918 6.3 Medium 2026-05-08
CVE-2026-42181 Lemmy: SSRF and internal image disclosure in post link metadata via unvalidated og:image — lemmy CWE-918 6.5 Medium 2026-05-08
CVE-2026-33693 Lemmy's Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid() — lemmy CWE-918 6.5 Medium 2026-03-27
CVE-2026-29178 Lemmy: Unauthenticated SSRF via file_type query parameter injection in image endpoint — lemmy CWE-918 7.5 - 2026-03-06
CVE-2025-25194 Server-Side Request Forgery (SSRF) in activitypub_federation — lemmy CWE-918 4.0 Medium 2025-02-10
CVE-2024-23649 Any authenticated user may obtain private message details from other users on the same instance — lemmy CWE-285 7.5 High 2024-01-24

This page lists every published CVE security advisory associated with LemmyNet. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.