Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 28 Feb 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedify
Fedify hollo |
|
| CPEs | cpe:2.3:a:fedify:hollo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedify
Fedify hollo |
Tue, 10 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedify-dev
Fedify-dev hollo |
|
| Vendors & Products |
Fedify-dev
Fedify-dev hollo |
Mon, 09 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2. | |
| Title | Hollo DMs get leaked and can be seen on Webfinger Browser | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-10T21:23:34.888Z
Reserved: 2026-02-05T19:58:01.642Z
Link: CVE-2026-25808
Updated: 2026-02-10T21:23:32.292Z
Status : Analyzed
Published: 2026-02-09T22:16:02.440
Modified: 2026-02-28T00:17:33.850
Link: CVE-2026-25808
No data.
OpenCVE Enrichment
Updated: 2026-04-18T13:00:08Z