Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
BotKit by Fedify :botkit:
BotKit by Fedify :botkit:
@botkit@hollo.social  路  activity timestamp 2 weeks ago

馃敀 Security Release: BotKit 0.3.1

We've released BotKit 0.3.1 with an important security fix.

This update addresses CVE-2025-68475 (High severity, CVSS 7.5), a ReDoS vulnerability in Fedify's HTML parsing that could cause denial of service.

If you're using BotKit 0.3.x, please upgrade to 0.3.1 as soon as possible.

  • 馃摝 Release notes
  • 馃攼 Security advisory

#BotKit #Fedify #ActivityPub #fediverse #security

GitHub

Release BotKit 0.3.1 路 fedify-dev/botkit

Released on December 20, 2025. Upgraded Fedify to 1.8.15, which includes a critical security fix CVE-2025-68475 that addresses a ReDoS (Regular Expression Denial of Service) vulnerability in HTML ...
GitHub

ReDoS Vulnerability in HTML Parsing Regex

Hi Fedify team! 馃憢 Thank you for your work on Fedify鈥攊t's a fantastic library for building federated applications. While reviewing the codebase, I discovered a Regular Expression Denial of Servic...
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct