CVE-2026-25808

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fedify:hollo:*:*:*:*:*:*:*:*
cpe:2.3:a:fedify:hollo:*:*:*:*:*:*:*:*

History

28 Feb 2026, 00:17

Type Values Removed Values Added
Summary
  • (es) Hollo es un software de microblogging de un solo usuario federado diseñado para ser federado a través de ActivityPub. Antes de 0.6.20 y 0.7.2, existe una vulnerabilidad de seguridad donde los mensajes directos (MD) y las publicaciones solo para seguidores fueron expuestos a través del endpoint de bandeja de salida de ActivityPub sin autorización. Esta vulnerabilidad está corregida en 0.6.20 y 0.7.2.
First Time Fedify hollo
Fedify
CPE cpe:2.3:a:fedify:hollo:*:*:*:*:*:*:*:*
References () https://github.com/fedify-dev/hollo/commit/329969c502ef092d5c3f9c2c20421c34f4ff0f0e - () https://github.com/fedify-dev/hollo/commit/329969c502ef092d5c3f9c2c20421c34f4ff0f0e - Patch
References () https://github.com/fedify-dev/hollo/releases/tag/0.6.20 - () https://github.com/fedify-dev/hollo/releases/tag/0.6.20 - Product, Release Notes
References () https://github.com/fedify-dev/hollo/releases/tag/0.7.2 - () https://github.com/fedify-dev/hollo/releases/tag/0.7.2 - Product, Release Notes
References () https://github.com/fedify-dev/hollo/security/advisories/GHSA-6r2w-3pcj-v4v5 - () https://github.com/fedify-dev/hollo/security/advisories/GHSA-6r2w-3pcj-v4v5 - Vendor Advisory, Exploit

09 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 22:16

Updated : 2026-02-28 00:17


NVD link : CVE-2026-25808

Mitre link : CVE-2026-25808

CVE.ORG link : CVE-2026-25808


JSON object : View

Products Affected

fedify

  • hollo
CWE
CWE-862

Missing Authorization