Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Hollo :hollo:

@hollo@hollo.social
hollo 0.10.0-dev.658
  • Open on hollo.social

:hollo: A federated single-user microblogging software.

708 Followers
0 Following
31 Posts
Joined May 29, 2024
Website:

https://hollo.social/

GitHub:

https://github.com/fedify-dev/hollo

Fedify:

https://fedify.dev/

Open post
Hollo :hollo: @hollo@hollo.social
· 4mo ago

Hollo 0.9.0 is out. https://github.com/fedify-dev/hollo/discussions/496

The biggest change this release is a complete redesign of every server-rendered page. Pico CSS is replaced by a new design system built on UnoCSS, and your chosen theme color now tints your profile and dashboard pages throughout.

Other highlights:

  • Passkey (WebAuthn) authentication: sign in with a biometric or PIN gesture, which counts as MFA so there's no separate TOTP step
  • Full FEP-044f quote authorization: QuoteRequest/Accept/Reject federation, quote policy enforcement, and dereferenceable QuoteAuthorization objects
  • A configurable media proxy (MEDIA_PROXY=proxy or cache) that re-serves remote avatars, attachments, and preview images from Hollo's own origin
  • Optional split-domain WebFinger via HANDLE_HOST + WEB_ORIGIN
  • Public followers/following pages and per-post reaction list pages (likes, boosts, emoji reactions, quotes)

There were also several serious database performance fixes: profile page queries that were taking hundreds of seconds on cold caches, a NodeInfo endpoint doing a full table scan on every request, and a handful of timeline pagination bugs.

#Hollo #ActivityPub #Fediverse

GitHub

Hollo 0.9.0: Redesigned UI, passkey authentication, FEP-044f quote authorization, and major performance improvements · fedify-dev/hollo · Discussion #496

Hollo is a single-user, headless ActivityPub server. It exposes a Mastodon-compatible API with no built-in frontend, so you can connect any Mastodon client of your choice. It's built on Fedify and ...

20
0
24
1
Open post
Hollo :hollo: @hollo@hollo.social
· 2mo ago
Boosted by @fedicat@pc.cafe
Hollo security updates: 0.8.9 and 0.9.9 If you run Hollo, update to a patched release now. CVE-2026-62857 affects Fedify's NodeInfo client, which Hollo uses to identify the software running on remote ActivityPub servers. A NodeInfo lookup starts by fetching a remote server's /.well-known/nodeinfo document, then follows the NodeInfo document URL advertised in that response. The vulnerable getNodeInfo() path fetched both URLs without validating that they resolved to public network destinations. Because the second URL comes directly from a response controlled by the remote server, it could point to a loopback address, a link-local cloud metadata endpoint, an RFC 1918 private address, or even a data: URL. An attacker who controls a remote server that Hollo discovers could therefore make the Hollo instance initiate requests to non-public network destinations, depending on the deployment environment and network routing. The fix applies Fedify's public-address validation to both NodeInfo requests and every redirect hop. It also caps redirects, refuses cross-protocol redirects, and rejects non-HTTP(S) URLs. As a result, NodeInfo lookups for private or intranet addresses are now refused. For full technical details of the underlying vulnerability, see the Fedify security advisory and the Fedify security announcement. All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.8 and 0.9.8 are affected. Patched releases are 0.8.9 for the 0.8.x series and 0.9.9 for the 0.9.x series. Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version. For 0.8.x deployments, update to 0.8.9: docker pull ghcr.io/fedify-dev/hollo:0.8.9 For 0.9.x deployments, update to 0.9.9: docker pull ghcr.io/fedify-dev/hollo:0.9.9 After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart. Thanks to @rvzsec and @manus-use for the report and responsible disclosure to the Fedify project. If anything is unclear, ask below.
3
0
5
0
Open post
Hollo :hollo: @hollo@hollo.social
· 4mo ago
Boosted by @fedicat@pc.cafe
Hollo security updates: 0.7.16 and 0.8.5 If you run Hollo, update to a patched release now. Hollo 0.7.16 and 0.8.5 fix several security issues in ActivityPub federation, the web admin UI, OAuth, and the transitive fast-xml-parser dependency. On the federation side, three inbox handlers were missing authorization checks. Any remote actor could send a Delete to remove any cached post by IRI, an Update to overwrite or first-materialize a cached post under another actor's name, or a cross-origin Announce whose attacker-controlled embedded body materialized as someone else's post. The checks now differ by activity type. A Delete is ignored unless the deleter's origin matches the cached post author's origin. An Update is ignored unless the activity actor, the embedded object's id, and its attributedTo all share an origin. For Announce, Hollo no longer trusts attacker-supplied embedded content to create or overwrite the original post: unknown cross-origin objects are fetched from their canonical URL, and any newly cached object must have matching id and attributedTo origins. Separately, Follow, Like, EmojiReact, and Announce from a blocked actor were processed normally and still produced notifications; they are now silently dropped at the inbox. On the web admin side, login and OTP cookies were set without HttpOnly, SameSite, or Secure, and state-changing forms had no Origin or Sec-Fetch-Site check. A single reflected XSS could exfiltrate the admin session, and a malicious page could submit a hidden cross-site form to disable 2FA, delete an account, or silently authorize a rogue OAuth application. The affected dashboard routes and POST /oauth/authorize now run Hono's CSRF middleware, and the login and OTP cookies now carry those attributes. The transitive fast-xml-parser (carried in via the AWS SDK that backs S3 storage) is now pinned to patched versions, closing one critical and several high-severity advisories. Hollo also now uses constant-time comparison for the OAuth PKCE check and the multi-credential client-secret consistency check, and it warns at startup when LOG_QUERY=true is set, because drizzle-orm logs bound parameter values, including OAuth tokens and other secrets. All Hollo versions up to and including 0.7.15 and 0.8.4 are affected. Patched releases are 0.7.16 for the 0.7.x series and 0.8.5 for the 0.8.x series. CHANGES.md has the longer notes, including the availability trade-off for cross-origin Announce validation when the canonical origin is unreachable. For 0.7.x deployments, update to 0.7.16: docker pull ghcr.io/fedify-dev/hollo:0.7.16 For 0.8.x deployments, update to 0.8.5: docker pull ghcr.io/fedify-dev/hollo:0.8.5 After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart. If anything is unclear, ask below.
5
1
6
3
Open post
Hollo :hollo: @hollo@hollo.social
· 5mo ago

Hollo 0.7.11 is now available and includes an important security update. If you are running an older version, please upgrade to 0.7.11 as soon as possible.

6
0
10
0
Open post
Hollo :hollo: @hollo@hollo.social
· 5mo ago

Hollo 0.8.0 is out. The main additions: you can now run web and worker processes separately via NODE_TYPE, which helps on instances with large follower counts where federation load was slowing down API responses. Mastodon clients that support the 4.5 quote post API will now work with Hollo. Remote actor profiles are refreshed automatically in the background when they go stale, and dead follower records are cleaned up on permanent delivery failures. There's also a new dashboard page for mass-deleting cached thumbnails from remote posts to free up storage.

https://github.com/fedify-dev/hollo/discussions/449

GitHub

Hollo 0.8.0: Scalable workers, Mastodon 4.5 quote post API support, and smarter federation · fedify-dev/hollo · Discussion #449

Hollo is a single-user, headless ActivityPub server. It exposes a Mastodon-compatible API with no built-in frontend, so you can connect any Mastodon client of your choice. It's built on Fedify and ...

5
0
8
0
Open post
Hollo :hollo: @hollo@hollo.social
· 8mo ago
Hollo 0.7.0: Advanced search, faster notifications, and improved client compatibility

It's been a while since our last release, and we're excited to finally share Hollo 0.7.0 with you. This release brings a lot of improvements that we've been working on over the past months—from powerful new search capabilities to significant performance gains that should make your daily Hollo experience noticeably snappier.

Let's dive into what's new.

HighlightsSearch gets a major upgrade

One of the most requested features has been better search, and we're happy to deliver. Hollo now supports Mastodon-compatible search operators, so you can finally filter your searches the way you've always wanted:

  • has:media/has:poll — Find posts with attachments or polls
  • is:reply/is:sensitive — Filter by post type
  • language:xx — Search in a specific language
  • from:username — Find posts from a specific person
  • mentions:username — Find posts mentioning someone
  • before:YYYY-MM-DD/after:YYYY-MM-DD — Search within a date range
  • Combine them with - for negation, OR for alternatives, and parentheses for grouping

For example, (from:alice OR from:bob) has:poll -is:reply will find polls from Alice or Bob that aren't replies.

We've also made search much faster. URL and handle searches that used to take 8–10 seconds now complete in about 1.4 seconds—an 85% improvement.

Notifications are faster than ever

We completely rebuilt how notifications work under the hood. Instead of computing notifications on every request, Hollo now stores them as they happen. The result? About 24% faster notification loading (down from 2.5s to 1.9s).

On top of that, we've implemented Mastodon's v2 grouped notifications API, which groups similar notifications together server-side. This means less work for your client app and a cleaner notification experience.

Everything loads faster with compression

All API responses are now compressed, reducing their size by 70–92%. Some real numbers: notification responses dropped from 767KB to 58KB, and home timeline responses went from 91KB to 14KB. You'll notice faster load times, especially on slower connections.

Quote notifications

When someone quotes your post, you'll now get a notification about it. And if the original author edits a post you've quoted, you'll be notified too. These are the new quote and quoted_update notification types from Mastodon 4.5.0.

Background import processing

Importing your data (follows, lists, muted/blocked accounts, bookmarks) used to block the entire request until it finished. Now imports run in the background, and you can watch the progress in real-time. Much better for large imports. Thanks to Juyoung Jung for implementing this in #295.

Other improvements
  • Upgraded Fedify to 1.10.0.
  • Instance API responses now include proper thumbnails, actual stats, and correct values for max_featured_tags and max_pinned_statuses. Thanks to Juyoung Jung for this improvement in #296.
  • The notifications API now includes a prev link in pagination headers, which was tracked in #312.
  • Replaced the deprecated fluent-ffmpeg package with direct ffmpeg calls. If video thumbnail generation fails, you'll get a default image instead of an error. Thanks to Peter Jeschke for this fix in #333.
Bug fixes
  • Emelia Smith fixed an issue where POST /api/v1/statuses and PUT /api/v1/statuses/:id were rejecting FormData requests in #171.
  • Fixed log files writing multiple JSON objects on a single line, as reported in #174.
  • Lee ByeongJun fixed POST /api/v1/statuses rejecting null values in optional fields in #179.
  • Juyoung Jung fixed OAuth token endpoint issues with clients that send credentials in both the header and body in #296.
  • Fixed OAuth token endpoint failing to parse requests from clients that don't send a Content-Type header.
  • Peter Jeschke fixed notification endpoints returning 500 errors for unknown notification types in #334.
  • Fixed /api/v2/search not respecting the limit parameter, as reported in #210.
UpgradingDocker

Pull the latest image and restart your container:

docker pull ghcr.io/fedify-dev/hollo:0.7.0
docker compose up -d
Railway

Go to your Railway dashboard, select your Hollo service, and click Redeploy from the deployments menu.

Manual installation

Pull the latest code and reinstall dependencies:

git pull origin stable
pnpm install
pnpm run prod
Thank you to our contributors

This release wouldn't have been possible without the contributions from our community. A big thank you to Emelia Smith (@thisismissem@hachyderm.io), Juyoung Jung (@quadr@hollo.redfeel.net), Lee ByeongJun (@joonnot@hackers.pub), and Peter Jeschke (@peter@jeschke.dev) for their pull requests and bug reports. We really appreciate your help in making Hollo better!

GitHub

feat: Implement async import jobs with background worker by quadr · Pull Request #295 · fedify-dev/hollo

Summary This PR implements asynchronous import job processing with a background worker to improve the reliability and performance of account data imports (following accounts, lists, muted/blocked a...

8
0
13
0
Open post
Hollo :hollo: @hollo@hollo.social
· 8mo ago

Hollo 0.7.0 will introduce advanced search operators!

You'll be able to filter posts using operators like has:media, is:sensitive, language:en, from:username, date ranges with before: and after:, and combine them with OR and negation (-).

For example: cat has:media -is:sensitive

Full documentation: https://canary.docs.hollo.social/search/.

Hollo

Search

Hollo supports advanced search queries with various operators to filter posts by author, content, attachments, date ranges, and more.

8
0
8
0
Open post
Hollo :hollo: @hollo@hollo.social
· 10mo ago

#Hollo 0.7 brings a redesigned #notification system with much better performance. We've moved from generating #notifications on-demand to storing them as they happen, which makes the notifications endpoint about 60% faster. We've also added response compression (though if you're using a reverse proxy, you probably had this already).

More notably, Hollo 0.7 implements Mastodon's v2 grouped notifications API. Notifications like favorites, follows, and reblogs targeting the same post or account are now grouped together server-side, reducing clutter. Clients that support the new API (introduced in #Mastodon 4.3) will show cleaner, more organized notifications automatically.

Hollo 0.7 is still in development, but we're excited to share it with you when it's ready!

hollo.social
12
0
13
0
Open post
Hollo :hollo: @hollo@hollo.social
· 7mo ago

The recent Hollo 0.7.3 and 0.7.4 updates have improved interoperability with #Bonfire. The issue where sending/receiving DMs or mutual following with Bonfire wasn't working properly has been resolved.

GitHub

Release Hollo 0.7.3 · fedify-dev/hollo

Released on February 23, 2026. Temporarily changed Fedify's firstKnock setting to draft-cavage-http-signatures-12 for outbound inbox deliveries as a compatibility workaround for Bonfire's current ...

6
5
4
0
Open post
Hollo :hollo: @hollo@hollo.social
· 6mo ago

Hollo has always been headless—no built-in frontend, just a Mastodon-compatible API. You pick your own client. That's kind of the point.

But we've been wondering: what if Hollo shipped its own web frontend? The Mastodon-compatible API would stay, so your current client setup wouldn't change. It'd just be one more option.

Would you use it?

4
2
7
0
Open post
Hollo :hollo: @hollo@hollo.social
· 4mo ago
Boosted by @fedicat@pc.cafe
Hollo security updates: 0.7.17, 0.8.6, and 0.9.1 If you run Hollo, update to a patched release now. CVE-2026-42462 affects Fedify's Linked Data Signature handling, and Hollo depends on Fedify for ActivityPub federation. Fedify verifies incoming ActivityPub activities with several mechanisms, including HTTP Signatures, Object Integrity Proofs, and Linked Data Signatures. The vulnerable path is Linked Data Signatures: the signature is checked over the canonical RDF graph, but JSON-LD can represent the same graph in more than one JSON shape. In affected versions, that gap could let a signed activity be reshaped so that Fedify reads a different ActivityPub object shape than intended—without invalidating the signature. The fix makes Fedify normalize Linked Data Signature-verified activities against its local JSON-LD context before interpreting them, and rejects JSON-LD constructs that can preserve the signed RDF graph while changing the ActivityPub object shape. For full technical details of the underlying vulnerability, see the Fedify security announcement. All Hollo versions up to and including 0.7.16, 0.8.5, and 0.9.0 are affected. Patched releases are 0.7.17 for the 0.7.x series, 0.8.6 for the 0.8.x series, and 0.9.1 for the 0.9.x series. For 0.7.x deployments, update to 0.7.17: docker pull ghcr.io/fedify-dev/hollo:0.7.17 For 0.8.x deployments, update to 0.8.6: docker pull ghcr.io/fedify-dev/hollo:0.8.6 For 0.9.x deployments, update to 0.9.1: docker pull ghcr.io/fedify-dev/hollo:0.9.1 After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart. Thanks to @Claire@social.sitedethib.com for the report and responsible disclosure to the Fedify project. If anything is unclear, ask below.
2
0
14
0
Open post
Hollo :hollo: @hollo@hollo.social
· 5mo ago
Hollo security updates: 0.7.15 and 0.8.3

If you run Hollo, update to a patched release now. A private network protection bypass in Fedify, the ActivityPub framework Hollo depends on, affects remote document loading. URLs with private IPv4 addresses encoded as IPv4-mapped IPv6 literals, such as http://[::ffff:7f00:1]/, could pass URL validation even though they refer to private or loopback addresses.

Hollo uses Fedify to fetch remote ActivityPub documents and related resources. An attacker who can make your Hollo instance fetch an attacker-controlled URL may be able to bypass the private address checks that are intended to reduce SSRF (Server-Side Request Forgery) risk.

All Hollo versions up to and including 0.7.14 and 0.8.2 are affected. Patched releases are 0.7.15 for the 0.7.x series and 0.8.3 for the 0.8.x series. For full technical details of the underlying vulnerability, see the Fedify security announcement.

For 0.7.x deployments, update to 0.7.15:

docker pull ghcr.io/fedify-dev/hollo:0.7.15

For 0.8.x deployments, update to 0.8.3:

docker pull ghcr.io/fedify-dev/hollo:0.8.3

After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart.

Thanks to Changkyun Kim (@me) for the report and responsible disclosure to the Fedify project.

If anything is unclear, ask below.

GitHub

Release Hollo 0.7.15 · fedify-dev/hollo

Released on May 10, 2026. Upgraded Fedify to 1.10.9 to fix a critical SSRF (Server-Side Request Forgery) vulnerability where private IPv4 addresses encoded as IPv6 literals could bypass security c...

2
0
10
0
Open post
Hollo :hollo: @hollo@hollo.social
· 9mo ago
Replying to
セキュリティアップデート: Hollo 0.6.19 リリース FedifyのHTMLパースコードにおけるセキュリティ脆弱性に対応したHollo 0.6.19をリリースしました。 この脆弱性 (CVE-2025-68475) は ReDoS (正規表現によるサービス拒否) の問題であり、攻撃者がフェデレーション操作中に特別に細工されたHTMLレスポンスを送信することで、サービス停止を引き起こす可能性があります。悪意のあるペイロードは小さい (約170バイト) ですが、Node.jsのイベントループを長時間ブロックする可能性があります。 すべてのHollo運営者の皆様には、直ちにバージョン 0.6.19 へのアップグレードを強くお勧めします。 項目 詳細 CVE CVE-2025-68475 深刻度 高 (CVSS 7.5) 対応 Hollo 0.6.19 にアップグレード #Hollo #セキュリティ #fediverse #ActivityPub
5
0
3
0
Open post
Hollo :hollo: @hollo@hollo.social
· 12mo ago

Hollo 0.6.11 significantly improves Bluesky interoperability via BridgyFed! Fixed AT Protocol URI parsing issues that were affecting various cross-platform interactions—not just likes, but overall federation with Bluesky users. 🌉

GitHub

Like activity not receive from brid.gy · Issue #217 · fedify-dev/hollo

version : Hollo 0.6.10 reproduction procedure Post something on Hollo Once the post is bridged to the bluesky side, add it to your favorites Not receiving like notification on Hollo remarks On Mast...

6
0
9
0
Open post
Hollo :hollo: @hollo@hollo.social
· 15mo ago

Just dropped Hollo 0.6.4 with a minor bug fix.

GitHub

Release Hollo 0.6.4 · fedify-dev/hollo

Released on July 7, 2025. Fixed a regression bug where follower-only posts were returning 404 Not Found errors when accessed through conversation threads. This was caused by improper OAuth scope ...

6
0
3
0
Open post
Hollo :hollo: @hollo@hollo.social
· 12mo ago
Security update: Hollo 0.6.12 is now available

We've released #Hollo 0.6.12 to fix a critical privacy #vulnerability where direct messages were being exposed in the replies section of public posts. Please update your instances immediately to ensure your private conversations remain private.

#security

hollo.social
4
0
9
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
🚨 보안 업데이트: Hollo 0.6.5 릴리스 CVE-2025-53941 #보안 취약점을 해결하는 #Hollo 0.6.5를 릴리스했습니다. 연합 게시물의 HTML 주입 취약점이 수정되었습니다. 피싱 및 XSS 공격으로부터 인스턴스를 보호하기 위해 즉시 업데이트해 주세요. 업데이트 방법: Railway: 배포 탭 → 점 세 개 클릭 → RedeployDocker: docker pull ghcr.io/fedify-dev/hollo:latest 후 재시작수동: git pull origin stable && pnpm install 후 서버 재시작 #업데이트
4
2
3
0
Open post
Hollo :hollo: @hollo@hollo.social
· 16mo ago

🚨 Known Issue: Elk (@elk@m.webtoo.ls) login may fail on Hollo instances upgraded from 0.5.x to 0.6.x with 401 Unauthorized errors. Fresh 0.6.x installs work fine. Other clients (Phanpy, Moshidon) are unaffected.

We're investigating: https://github.com/fedify-dev/hollo/issues/167

Workaround: Use alternative clients like Phanpy (@phanpy@hachyderm.io) for now.

github.com
4
1
6
0
Open post
Hollo :hollo: @hollo@hollo.social
· 7mo ago
Replying to
@benpate@mastodon.social Yes, of course we're interested in #E2EE too! (For reference, Hollo doesn't have E2EE for DMs yet.) We're completely open to collaborating with the #Bonfire team.
1
3
0
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
Fedify 프레임워크의 #보안 #취약점을 해결하기 위해 #Hollo 보안 업데이트를 릴리스했습니다 (0.4.12, 0.5.7, 0.6.6). 이번 업데이트는 CVE-2025-54888을 수정하는 최신 Fedify 보안 패치를 포함합니다. 모든 Hollo 인스턴스 관리자분들께서는 가능한 한 빨리 해당 릴리스 브랜치의 최신 버전으로 업데이트하시기를 강력히 권장합니다. 업데이트 방법: Railway 사용자: 프로젝트 대시보드에서 Hollo 서비스를 선택하고, deployments의 점 세 개 메뉴를 클릭한 후 “Redeploy”를 선택하세요Docker 사용자: docker pull ghcr.io/fedify-dev/hollo:latest로 최신 이미지를 받고 컨테이너를 재시작하세요수동 설치 사용자: git pull로 최신 코드를 받은 후 pnpm install을 실행하고 서비스를 재시작하세요
2
2
3
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
Fedifyフレームワークの脆弱性に対処するため、Holloのセキュリティアップデートをリリースしました。(0.4.12、0.5.7、0.6.6)これらのアップデートには、CVE-2025-54888を修正する最新のFedifyセキュリティパッチが含まれています。 すべてのHolloインスタンス管理者の皆様には、できるだけ早く該当するリリースブランチの最新バージョンにアップデートしていただくことを強く推奨いたします。 アップデート方法: Railwayユーザー: プロジェクトダッシュボードでHolloサービスを選択し、deploymentsの三点メニューをクリックして「Redeploy」を選択してくださいDockerユーザー: docker pull ghcr.io/fedify-dev/hollo:latestで最新イメージを取得し、コンテナを再起動してください手動インストールユーザー: git pullで最新コードを取得した後、pnpm installを実行してサービスを再起動してください #Fedify #セキュリティ #脆弱性
2
1
7
0
Open post
Hollo :hollo: @hollo@hollo.social
· 9mo ago
Replying to
보안 업데이트: Hollo 0.6.19 릴리스 Fedify의 HTML 파싱 코드에서 발견된 보안 취약점을 수정한 Hollo 0.6.19를 릴리스했습니다. 이 취약점(CVE-2025-68475)은 ReDoS(정규 표현식 서비스 거부) 문제로, 공격자가 연합 작업 중 특수하게 조작된 HTML 응답을 보내 서비스 장애를 유발할 수 있습니다. 악성 페이로드는 작지만(약 170바이트), Node.js 이벤트 루프를 장시간 차단할 수 있습니다. 모든 Hollo 운영자분들께 즉시 버전 0.6.19로 업그레이드하실 것을 강력히 권고드립니다. 항목 상세 CVE CVE-2025-68475 심각도 높음 (CVSS 7.5) 조치 Hollo 0.6.19로 업그레이드 #Hollo #보안 #페디버스 #연합우주 #ActivityPub
1
1
1
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
🚨 安全更新:Hollo 0.6.5 发布 我们发布了 #Hollo 0.6.5,修复了 CVE-2025-53941 关键安全漏洞,解决了联邦帖子中的 HTML 注入漏洞。 请立即更新以保护您的实例免受潜在的钓鱼和 XSS 攻击。 更新方法: Railway:转到部署 → 点击三个点 → RedeployDocker:docker pull ghcr.io/fedify-dev/hollo:latest 然后重启手动:git pull origin stable && pnpm install 然后重启服务器 #安全 #更新
2
0
3
0
Open post
Hollo :hollo: @hollo@hollo.social
· 16mo ago

What client apps do you use with #Hollo?

hollo.social
2
0
14
0
Open post
Hollo :hollo: @hollo@hollo.social
· 12mo ago

@nshki@ruby.social Thanks for your interest in Hollo!

While we don't have officially documented minimum requirements yet, Hollo is designed for single-user instances and is significantly lighter than multi-user software like Mastodon or Misskey.

Rough guidelines:

  • RAM: 2GB recommended (including Node.js and PostgreSQL)
  • CPU: 1 vCPU/core should be sufficient
  • Storage: 10GB+ (depending on media storage needs)
  • Database: PostgreSQL 17+

Real-world deployment:

  • Works well on basic VPS plans ($5–10/month tier)
  • Runs smoothly on DigitalOcean Droplets, Linode, Vultr starter plans
  • Railway's Hobby plan handles it fine
  • ARM processors are supported (the official hollo.social instance runs on ARM)

Storage considerations:

  • If storing media locally, plan for additional disk space
  • Using S3-compatible object storage can help reduce local storage requirements
  • Resource usage scales with the number of accounts you follow and federation activity

Since it's single-user software, you can start with minimal resources and adjust as needed based on your actual usage patterns.

1
0
0
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
🚨 セキュリティアップデート:Hollo 0.6.5 リリース CVE-2025-53941のセキュリティ脆弱性を修正したHollo 0.6.5をリリースしました。連合投稿のHTMLインジェクション脆弱性が修正されています。 フィッシングやXSS攻撃からインスタンスを保護するため、今すぐアップデートしてください。 アップデート方法: Railway:デプロイメント → 縦3点クリック → RedeployDocker:docker pull ghcr.io/fedify-dev/hollo:latest して再起動手動:git pull origin stable && pnpm install してサーバー再起動 #Hollo #セキュリティ #アップデート
1
1
5
0
Open post
Hollo :hollo: @hollo@hollo.social
· 14mo ago
Replying to
为了解决底层 Fedify 框架的安全漏洞,我们发布了 Hollo 安全更新。(0.4.12、0.5.7 和 0.6.6)这些更新包含了修复 CVE-2025-54888 的最新 Fedify 安全补丁。 我们强烈建议所有 Hollo 实例管理员尽快更新到相应发布分支的最新版本。 更新方法: Railway 用户:进入项目仪表板,选择您的 Hollo 服务,点击部署中的三点菜单,然后选择"Redeploy"Docker 用户:使用 docker pull ghcr.io/fedify-dev/hollo:latest 拉取最新镜像并重启容器手动安装用户:运行 git pull 获取最新代码,然后执行 pnpm install 并重启服务 #Hollo #安全更新 #安全补丁 #漏洞修复 #Fedify
0
0
1
0
Open post
Hollo :hollo: @hollo@hollo.social
· 1w ago
Hollo security updates: 0.8.12 and 0.9.19 If you run Hollo, update to a patched release now. Fedify has disclosed three vulnerabilities that affect Hollo: CVE-2026-96625, a critical actor impersonation vulnerability; CVE-2026-96623, a high-severity denial-of-service vulnerability in remote document parsing; and CVE-2026-96624, a medium-severity server-side request forgery vulnerability in outbound activity delivery. Treat the actor impersonation issue as an immediate upgrade: anyone on the internet could have an activity accepted by your Hollo inbox as coming from any actor. For CVE-2026-96625, Fedify verified the signature on an incoming activity, but trusted the signing key document's own claim about whom the key belonged to. An attacker with an ordinary HTTP server could serve a key document naming any actor as its owner and have activities accepted under that actor's identity. No account on the receiving Hollo instance was required. The same flaw affected signed-key ownership checks used to restrict access to posts, allowing a forged key document to pass those checks under another actor's identity. The fix resolves the claimed owner's actor document and requires it to link back to the key. It also validates the origin of fetched actor documents. Fedify's built-in key cache automatically stops reading entries whose ownership had not been verified, so Hollo operators do not need to clear that cache manually. For CVE-2026-96623, Fedify parsed JSON bodies without a byte limit, including inbox bodies and remote documents such as keys, actors, objects, JSON-LD contexts, WebFinger descriptors, and NodeInfo documents. An attacker could exhaust memory and CPU with a large body, including a compressed response that expanded substantially before parsing. An inbound body limit at a reverse proxy did not protect the outbound fetch paths. The fix limits JSON bodies to 16 MiB after decompression. Oversized inbox requests receive HTTP 413, and remote JSON documents larger than this limit are rejected. For CVE-2026-96624, outbound activity delivery validated neither the inbox URL advertised by a remote actor nor its redirect destinations. A remote actor could point its inbox at a loopback address, a link-local cloud metadata service, or a private network host, or redirect delivery there. On the RSA delivery path, the redirected request remained a POST carrying the activity body and was re-signed for the internal host. The fix validates the initial destination and every redirect target before sending a request. This is a separate path from the authenticated document loader fixed in the previous Hollo security update. Hollo's existing ALLOW_PRIVATE_ADDRESS=true option still permits private destinations, including private inbox URLs and redirect targets. Use it only in test environments or closed federations where you control the remote actors. For full technical details, see the Fedify security advisories for CVE-2026-96625, CVE-2026-96623, and CVE-2026-96624, and the Fedify security announcement. All Hollo versions in the supported 0.8.x and 0.9.x release lines up to and including 0.8.11 and 0.9.18 are affected. Patched releases are 0.8.12 for the 0.8.x series and 0.9.19 for the 0.9.x series, incorporating Fedify 2.1.24 and 2.2.13 respectively. Hollo 0.7.x is also affected. It and earlier release lines are no longer supported under the Hollo security policy. Upgrade to a supported release series rather than remaining on an older version. For 0.8.x deployments, update to 0.8.12: docker pull ghcr.io/fedify-dev/hollo:0.8.12 For 0.9.x deployments, update to 0.9.19: docker pull ghcr.io/fedify-dev/hollo:0.9.19 After pulling the new image, restart your Hollo container. If you deploy from source, pull the corresponding release tag and restart. Thanks to @kaimandalic and @moreal@hackers.pub for independently reporting the actor impersonation issue, to @kaimandalic for reporting the unbounded document parsing issue, and to @euriconicacio for reporting the outbound delivery SSRF issue, and to all three for their responsible disclosure to the Fedify project. If anything is unclear, ask below.
GitHub

Arbitrary actor impersonation via unverified key ownership in inbox signature checks

### Summary Fedify's ActivityPub inbox verifies the HTTP signature on a delivery but never verifies that the key that produced the signature actually belongs to the actor claimed by `activity.ac...

0
0
3
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 05:35:43 UTC