CVE-2025-70886: High severity Halo Halo vulnerability
Published Feb 12, 2026
·Updated
An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
Affected Software
2 affected components
Halo Halo<2.22.4
Halo Halo<=2.22.4
Event History
Feb 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70886?
CVE-2025-70886 is considered a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2025-70886?
To fix CVE-2025-70886, upgrade Halo to version 2.22.5 or later to mitigate the vulnerability.
3
What software is affected by CVE-2025-70886?
CVE-2025-70886 affects Halo versions 2.22.4 and earlier.
4
How does CVE-2025-70886 affect my application?
CVE-2025-70886 allows remote attackers to disrupt service through crafted payloads to the public comment submission endpoint.
5
Is there a workaround for CVE-2025-70886 before upgrading?
As a temporary measure, disabling the public comment submission feature may mitigate the impact of CVE-2025-70886.