Description
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF protection introduced by the fix for CVE-2025-25194 (GHSA-7723-35v7-qcxw), and reach localhost services on the target server. Version 0.7.0-beta.9 patches the issue.
INFO
Published Date :
2026-03-27T00:03:35.946Z
Last Modified :
2026-03-30T11:51:10.425Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33693 vulnerability.
| Vendors | Products |
|---|---|
| Lemmynet |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33693.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact