CVE-2026-25808
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
09/02/2026
Última modificación:
10/02/2026
Descripción
*** Pendiente de traducción *** Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and 0.7.2.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA



