FedMsg not properly completing message validation
        
  High severity
        
          GitHub Reviewed
      
        Published
          Jul 13, 2018 
          to the GitHub Advisory Database
          •
          Updated Sep 20, 2024 
      
  
Description
        Published to the GitHub Advisory Database
      Jul 13, 2018 
    
  
        Reviewed
      Jun 16, 2020 
    
  
        Last updated
      Sep 20, 2024 
    
  
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
References