CVE-2025-70886

A

n issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

References
Link Resource
https://github.com/HowieHz/CVE-2025-70886 Exploit Third Party Advisory
https://github.com/halo-dev/halo/issues/7890 Exploit Issue Tracking Vendor Advisory
https://howiehz.top/archives/halo-comment-payload-tweaker Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*

History

18 Feb 2026, 15:45

Type Values Removed Values Added
CPE cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*
References () https://github.com/HowieHz/CVE-2025-70886 - () https://github.com/HowieHz/CVE-2025-70886 - Exploit, Third Party Advisory
References () https://github.com/halo-dev/halo/issues/7890 - () https://github.com/halo-dev/halo/issues/7890 - Exploit, Issue Tracking, Vendor Advisory
References () https://howiehz.top/archives/halo-comment-payload-tweaker - () https://howiehz.top/archives/halo-comment-payload-tweaker - Exploit, Third Party Advisory
First Time Halo
Halo halo

13 Feb 2026, 14:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 16:16

Updated : 2026-02-18 15:45


NVD link : CVE-2025-70886

Mitre link : CVE-2025-70886

CVE.ORG link : CVE-2025-70886


JSON object : View

Products Affected
CWE
CWE-400

Uncontrolled Resource Consumption