Skip to content

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone

- Are you the admin on a public Fediverse server which has sign-ups open?- Would you like your server listed on https://fedi.garden ?- Is your server compatible with all seven points at https://fedi.garden/about-this-site

Uncategorized
2 2 13

Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
  • 1 Votes
    1 Posts
    4 Views
    🚨 Security Advisory: CVE-2025-68475 A ReDoS (Regular Expression Denial of Service) vulnerability has been discovered in Fedify's HTML parsing code. This vulnerability could allow a malicious federated server to cause denial of service by sending specially crafted HTML responses. CVE ID CVE-2025-68475 Severity High (CVSS 7.5) Affected versions ≤1.9.1 Patched versions 1.6.13, 1.7.14, 1.8.15, 1.9.2 If you're running Fedify in production, please upgrade to one of the patched versions immediately. For full details, see the security advisory: https://github.com/fedify-dev/fedify/security/advisories/GHSA-rchf-xwx2-hm93 Thank you to Yue (Knox) Liu for responsibly reporting this vulnerability. #Fedify #ActivityPub #security #fediverse #fedidev
  • #Fediverse

    Fediverso fediverse
    3
    1
    0 Votes
    3 Posts
    4 Views
    @KrajciTom @luftvaffel excellent 😂💖🙌
  • Bonfire Social 1.0rc3 release

    Fediverso fediverse
    1
    0 Votes
    1 Posts
    11 Views
    This post did not contain any content.
  • 0 Votes
    1 Posts
    16 Views
    I think that if we really want to stop #chatcontrol we need to change how we tell the story. On the #fediverse we are a bunch of tech savvy people and we can articulate, understand and also have arguments on technical matters, but the real consensus pools are somewhere else, and they speak another language.Chatcontrol is like violating mail confidentiality. All regulations of nearly all countries guarantee that letters and correspondence are confidential. This is what should be told to people, that the regulation aims at removing this right. It's like the post office will read and evaluate each and every envelope they receive (and who says that they will not?).