7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.
Basic Information
ID
CVE-2026-25808
Source
GitHub_M
Published
Feb 9, 2026 at 21:50
Affected Product
Vendor
fedify-dev
Product
hollo
Version
< 0.6.20, 0.7.2
Affected Versions
fedify-dev hollo < 0.6.20, 0.7.2
fedify-dev hollo >= 7.0.0, < 0.7.2
fedify-dev hollo >= 7.0.0, < 0.7.2