CVE-2026-25808: Fedify Hollo
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.
Affected products
- Fedify Hollo: from 0.6.0, before 0.6.20 (fixed in 0.6.20); from 0.7.0, before 0.7.2 (fixed in 0.7.2)
Published 2026-02-09. Last modified 2026-06-17.