Released on October 1, 2026.
- Upgraded Fedify to 2.1.26, which fixes a security vulnerability where
Context.routeActivity()authenticated the dereferenced activity but routed the caller's unauthenticated copy, so an attacker who knew theidof any dereferenceable activity could have the application's inbox listeners process an activity with thatidbut with an actor, object, and addressing of the attacker's choice, and the genuine activity could then be dropped as a duplicate. The verified fetched document is now the one that gets queued, handed to listeners, and forwarded. [GHSA-39gj-rchc-q5m3]