Problem
Looking up a Hackers' Pub post from Hollo fails when the remote FEP-7aa9 JSON-LD context returns HTTP 502.
The affected post is:
https://hackers.pub/@botkit/2026/CVE-2026-96625
Both the post's ActivityPub document and its author's actor document return HTTP 200. However, the actor document includes https://w3id.org/fep/7aa9 in its @context. When requested as application/ld+json, that URL redirects to:
https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld
During the incident, this endpoint repeatedly returned HTTP 502 with an empty body. Fedify consequently failed to deserialize the actor, causing Hollo's /api/v2/search request with resolve=true to fail.
The same 502 response was reproduced by fetching the context directly from inside the Hollo container.
Error
Shortened logs from September 27, 2026, at 10:46:25 UTC:
ERR fedify·runtime·docloader: Failed to fetch document: 502 'https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld'
ERR fedify·federation·http: An error occurred while serving request 'GET'
'https://hollo.social/api/v2/search?q=https%3A%2F%2Fhackers.pub%2F%40botkit%2F2026%2FCVE-2026-96625&resolve=true&limit=5':
jsonld.InvalidUrl: Dereferencing a URL did not result in a valid JSON-LD object.
URL: "https://w3id.org/fep/7aa9".
details: {
code: 'loading remote context failed',
url: 'https://w3id.org/fep/7aa9',
cause: FetchError: https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld: HTTP 502
}
Expected behavior
Fedify should resolve the FEP-7aa9 context locally, so parsing documents that reference it does not depend on the availability of the remote context server.
Suggested solution
Bundle the FEP-7aa9 JSON-LD context as a static asset under packages/vocab-runtime/src/contexts/ and register https://w3id.org/fep/7aa9 in preloadedContexts in packages/vocab-runtime/src/contexts.ts.
Add a regression test confirming that the default document loader resolves this context without a network request, and a changelog entry for @fedify/vocab-runtime.
This addresses the same availability failure as the FEP-ef61 context issue in #982. The context-preloading change could be handled independently of the broader FEP-7aa9 vocabulary work in #810.
Problem
Looking up a Hackers' Pub post from Hollo fails when the remote FEP-7aa9 JSON-LD context returns HTTP 502.
The affected post is:
https://hackers.pub/@botkit/2026/CVE-2026-96625
Both the post's ActivityPub document and its author's actor document return HTTP 200. However, the actor document includes
https://w3id.org/fep/7aa9in its@context. When requested asapplication/ld+json, that URL redirects to:https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld
During the incident, this endpoint repeatedly returned HTTP 502 with an empty body. Fedify consequently failed to deserialize the actor, causing Hollo's
/api/v2/searchrequest withresolve=trueto fail.The same 502 response was reproduced by fetching the context directly from inside the Hollo container.
Error
Shortened logs from September 27, 2026, at 10:46:25 UTC:
Expected behavior
Fedify should resolve the FEP-7aa9 context locally, so parsing documents that reference it does not depend on the availability of the remote context server.
Suggested solution
Bundle the FEP-7aa9 JSON-LD context as a static asset under
packages/vocab-runtime/src/contexts/and registerhttps://w3id.org/fep/7aa9inpreloadedContextsinpackages/vocab-runtime/src/contexts.ts.Add a regression test confirming that the default document loader resolves this context without a network request, and a changelog entry for
@fedify/vocab-runtime.This addresses the same availability failure as the FEP-ef61 context issue in #982. The context-preloading change could be handled independently of the broader FEP-7aa9 vocabulary work in #810.