CVE List

CVE-2026-25808

Critical 7.5

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.

Published February 9, 2026.

Affected software

Get alerts for Fedify Hollo

Reference links