CVE-2026-25808: Fedify Hollo

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.

Affected products

  • Fedify Hollo: from 0.6.0, before 0.6.20 (fixed in 0.6.20); from 0.7.0, before 0.7.2 (fixed in 0.7.2)

Published 2026-02-09. Last modified 2026-06-17.