Skip to content

hollo

v0.8.9 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

activitypub fediverse microblog

Affected surfaces

rce_ssrf breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 8d

Fedify was upgraded to version 2.1.18, which resolves a remote code execution flaw in NodeInfo lookups.

Why it matters: The upgrade patches a critical RCE (severity 95) affecting the Fedify dependency; deploy release 0.8.9 immediately.

Summary

AI summary

Fixed security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations.

Changes in this release

Security Critical

Upgraded Fedify to 2.1.18 fixing a remote code execution vulnerability in NodeInfo lookups.

Upgraded Fedify to 2.1.18 fixing a remote code execution vulnerability in NodeInfo lookups.

Source: llm_adapter@2026-07-18

Confidence: high

Full changelog

Released on July 19, 2026.

  • Upgraded Fedify to 2.1.18 to fix a security vulnerability in NodeInfo lookups that could allow remote instances to make Hollo fetch non-public network destinations. [CVE-2026-62857]

Security Fixes

  • CVE-2026-62857 — remote instances could cause Hollo to fetch non-public network destinations via NodeInfo lookups

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track hollo

Get notified when new releases ship.

Sign up free

About hollo

Federated single-user microblogging software

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]