Home

Description

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

PUBLISHED Reserved 2026-01-09 | Published 2026-02-12 | Updated 2026-02-12 | Assigner mitre

References

github.com/halo-dev/halo/issues/7890

howiehz.top/archives/halo-comment-payload-tweaker

github.com/HowieHz/CVE-2025-70886

cve.org (CVE-2025-70886)

nvd.nist.gov (CVE-2025-70886)

Download JSON