{"id":"CVE-2026-25808","summary":"Hollo DMs get leaked and can be seen on Webfinger Browser","details":"Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.","aliases":["GHSA-6r2w-3pcj-v4v5"],"modified":"2026-08-12T03:51:34.354628318Z","published":"2026-02-09T21:50:10.579Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25808.json","unresolved_ranges":[{"extracted_events":[{"introduced":"\u003c 0.6.20, 0.7.2"},{"last_affected":"\u003c 0.6.20, 0.7.2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/fedify-dev/hollo/releases/tag/0.6.20"},{"type":"WEB","url":"https://github.com/fedify-dev/hollo/releases/tag/0.7.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25808.json"},{"type":"ADVISORY","url":"https://github.com/fedify-dev/hollo/security/advisories/GHSA-6r2w-3pcj-v4v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25808"},{"type":"FIX","url":"https://github.com/fedify-dev/hollo/commit/329969c502ef092d5c3f9c2c20421c34f4ff0f0e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fedify-dev/hollo","events":[{"introduced":"d61781b391f59bd13586cb6b54c8b9d7c1b3843f"},{"fixed":"6f40242f033335958216e92d55c2f875d60a40bc"},{"introduced":"77645493026cf9138fecdf8028c4ad9769d159c0"},{"fixed":"4d02a2d28e347c90bf81697e52a66de2bbf4928f"},{"fixed":"329969c502ef092d5c3f9c2c20421c34f4ff0f0e"}],"database_specific":{"cpe":"cpe:2.3:a:fedify:hollo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.6.0"},{"fixed":"0.6.20"},{"introduced":"0.7.0"},{"fixed":"0.7.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.7.1","0.7.0","0.6.19","0.6.18","0.6.17","0.6.16","0.6.15","0.6.14","0.6.13","0.6.12","0.6.11","0.6.10","0.6.9","0.6.8","0.6.7","0.6.6","0.6.5","0.6.4","0.6.3","0.6.2","0.6.1","0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25808.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}