Incorrect Behavior Order: Validate Before Canonicalize Affecting @fedify/fedify package, versions <1.9.11>=1.10.0 <1.10.10>=2.0.0 <2.0.18>=2.1.0 <2.1.14>=2.2.0 <2.2.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-FEDIFYFEDIFY-16895732
  • published27 May 2026
  • disclosed26 May 2026
  • creditUnknown

Introduced: 26 May 2026

NewCVE-2026-42462  (opens in a new tab)
CWE-180  (opens in a new tab)

How to fix?

Upgrade @fedify/fedify to version 1.9.11, 1.10.10, 2.0.18, 2.1.14, 2.2.3 or higher.

Overview

@fedify/fedify is an An ActivityPub server framework

Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize through manipulation of JSON-LD document structure using keywords such as @graph, @included, and @reverse. An attacker can alter the interpretation of signed activities, potentially modifying or removing attributes, replaying activities, or forging arbitrary content by restructuring the payload while preserving its signature. This can result in unauthorized changes to activity data, loss of integrity, and disruption of service by exploiting the way the application processes and verifies signed JSON-LD documents.

CVSS Base Scores

version 4.0
version 3.1