This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalFedify was upgraded to version 2.2.7, which resolves a remote code execution flaw in NodeInfo lookups.
Why it matters: Fixes a critical RCE (severity 90) affecting the Fedify dependency; upgrade immediately if used.
Summary
AI summaryFixed a security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Upgraded Fedify to 2.2.7 fixing a remote code execution vulnerability in NodeInfo lookups. Upgraded Fedify to 2.2.7 fixing a remote code execution vulnerability in NodeInfo lookups. Source: llm_adapter@2026-07-18 Confidence: low |
— |
| Security | High |
Upgraded Fedify to 2.2.7 fixing a remote vulnerability in NodeInfo lookups that could cause Hollo to fetch non-public network destinations. Upgraded Fedify to 2.2.7 fixing a remote vulnerability in NodeInfo lookups that could cause Hollo to fetch non-public network destinations. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
Released on July 19, 2026.
- Upgraded Fedify to 2.2.7 to fix a security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations. [CVE-2026-62857]
Security Fixes
- CVE-2026-62857 – NodeInfo lookup vulnerability allowing remote instances to cause Hollo to fetch non-public network destinations (fixed by upgrading Fedify to 2.2.7)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]