A vulnerability, which was classified as critical, was found in Pixelfed. Affected by this issue is the function
validateUrl of the component SearchController. The manipulation of the argument remote-search results in server-side request forgery.
This vulnerability was named CVE-2026-71246. The attack may be performed from remote. There is no available exploit.