This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalFedify was upgraded to version 2.1.18, which resolves a remote code execution flaw in NodeInfo lookups.
Why it matters: The upgrade patches a critical RCE (severity 95) affecting the Fedify dependency; deploy release 0.8.9 immediately.
Summary
AI summaryFixed security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Upgraded Fedify to 2.1.18 fixing a remote code execution vulnerability in NodeInfo lookups. Upgraded Fedify to 2.1.18 fixing a remote code execution vulnerability in NodeInfo lookups. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Released on July 19, 2026.
- Upgraded Fedify to 2.1.18 to fix a security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations. [CVE-2026-62857]
Security Fixes
- CVE-2026-62857 — remote instances could cause Hollo to fetch non-public network destinations via NodeInfo lookups
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]