Security: LemmyNet/lemmy
Security
.github/SECURITY.md
-
Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfoGHSA-2hrg-7x4g-9vpg published
Jun 9, 2026 by NutomicModerate -
Stored XSS via markdown image alt-text in lemmy-ui html5-embedGHSA-2g66-9fr3-ppwj published
Jun 9, 2026 by NutomicLow -
Login Endpoint User Enumeration via HTTP Response Code DifferentialGHSA-xgg7-8hvq-8m65 published
Jun 9, 2026 by NutomicModerate -
Multi-community `Update` has no actor authorizationGHSA-5qxq-g3f3-57p5 published
May 19, 2026 by NutomicLow -
Private community profile and moderators leak via federation HTTPGHSA-9wj2-3cv5-cqrx published
May 18, 2026 by NutomicLow -
`CollectionAdd::Featured` does not check the post is in the communityGHSA-gwfj-h8r7-792v published
Jun 9, 2026 by NutomicLow -
Private community data exposed through community, saved, liked, and modlog API viewsGHSA-95q8-x6r6-672m published
Apr 29, 2026 by NutomicLow -
Blocked users can edit private messages sent before the blockGHSA-46g9-847m-qf8r published
Jun 9, 2026 by NutomicLow -
Private Lemmy instances expose multi-community metadata without authenticationGHSA-jmxc-hhwx-gvv3 published
Apr 29, 2026 by NutomicLow -
Lower-ranked federated moderator can remove higher-ranked moderatorsGHSA-xmpx-2j2f-c7g7 published
Jun 9, 2026 by NutomicModerate
Learn more about advisories related to LemmyNet/lemmy in the GitHub Advisory Database