CVE-2025-70886

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint
References
Link Resource
https://github.com/HowieHz/CVE-2025-70886 Exploit Third Party Advisory
https://github.com/halo-dev/halo/issues/7890 Exploit Issue Tracking Vendor Advisory
https://howiehz.top/archives/halo-comment-payload-tweaker Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-12 16:16

Updated : 2026-02-18 15:45


NVD link : CVE-2025-70886

Mitre link : CVE-2025-70886

CVE.ORG link : CVE-2025-70886


JSON object : View

Products Affected

halo

  • halo
CWE
CWE-400

Uncontrolled Resource Consumption