Security Digest: December 22, 2025 - 1 Critical Vulnerability

A high-severity Regular Expression Denial of Service (ReDoS) vulnerability has been identified in the Fedify library, potentially allowing attackers to incapacitate Node.js applications using Fedify by blocking the event loop.

· 2 min read

Security Digest: December 22, 2025 - Critical ReDoS Vulnerability in Fedify

Executive Summary

A high-severity Regular Expression Denial of Service (ReDoS) vulnerability has been identified in the Fedify library, potentially allowing attackers to incapacitate Node.js applications using Fedify by blocking the event loop. Immediate action is required to mitigate this threat.

Critical Vulnerabilities

  • CVE-2025-68475: ReDoS Vulnerability in Fedify Document Loader
    • Impact: Attackers can exploit this vulnerability to cause a Denial of Service (DoS) by sending specially crafted HTML responses that block the Node.js event loop.
    • Affected Systems: Applications using the Fedify library for federated application development, especially those using lookupObject() or documentLoader() functions.
    • Immediate Action: Implement size limits on HTML responses and consider replacing regex parsing with a DOM parser.
    • Mitigation: Upgrade to a patched version of Fedify when available or apply the recommended code changes to prevent ReDoS attacks.

Previously Alerted

What to Do Now

  1. Immediately review and implement patches or workarounds for the Fedify library.
  2. Verify that HTML response sizes are limited in your application to prevent excessive processing times.
  3. Monitor application logs for signs of DoS attacks and unusual request patterns.

Related Resources

  • Internal blog post on mitigating ReDoS vulnerabilities (coming soon)
  • Fedify GitHub Advisory for CVE-2025-68475 (to be published)

Keep reading