CVE-2025-70886

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
References
Link Resource
https://github.com/HowieHz/CVE-2025-70886 Exploit Third Party Advisory
https://github.com/halo-dev/halo/issues/7890 Exploit Issue Tracking Vendor Advisory
https://howiehz.top/archives/halo-comment-payload-tweaker Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*

History

18 Feb 2026, 15:45

Type Values Removed Values Added
References () https://github.com/HowieHz/CVE-2025-70886 - () https://github.com/HowieHz/CVE-2025-70886 - Exploit, Third Party Advisory
References () https://github.com/halo-dev/halo/issues/7890 - () https://github.com/halo-dev/halo/issues/7890 - Exploit, Issue Tracking, Vendor Advisory
References () https://howiehz.top/archives/halo-comment-payload-tweaker - () https://howiehz.top/archives/halo-comment-payload-tweaker - Exploit, Third Party Advisory
First Time Halo
Halo halo
CPE cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*

12 Feb 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

12 Feb 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 16:16

Updated : 2026-02-18 15:45


NVD link : CVE-2025-70886

Mitre link : CVE-2025-70886

CVE.ORG link : CVE-2025-70886


JSON object : View

Products Affected

halo

  • halo
CWE
CWE-400

Uncontrolled Resource Consumption