What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

ไปŠๅคœใฏ็„กๅฐ่‰ฏๅ“ใจใ„ใ†ๅใฎใ‚ซใƒฌใƒผๅฑ‹ใ•ใ‚“ใง่ฒทใฃใฆใใŸใ‚ซใƒฌใƒผใงๆ™ฉใ”ใฏใ‚“๐Ÿ›

ใƒžใƒƒใ‚ทใƒฅใ—ใŸๅคง่ฑ†ใซใƒใƒผใ‚บใ€ใƒ‘ใ‚ฏใƒใƒผใ‚’ๆททใœใ€ใ‚นใƒ‘ใ‚คใ‚นใง้ขจๅ‘ณใฅใ‘ใ—ใŸๅ…ทใ‚’ๅŒ…ใ‚“ใงๆšใ’็„ผใใ—ใŸใ‚ตใƒขใ‚ต้ขจใฎใ‚นใƒ‘ใ‚คใ‚ทใƒผๅŒ…ใฟๆšใ’ใ‚‚ไธ€็ท’ใซใ„ใŸใ ใใพใƒผใ™



0

NAS๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด PC ์ธํ„ฐ๋„ท์ด ์•ˆ๋˜๋„ค -_- ์ „์—๋Š” ๋ถ„๋ช… ์•ˆ๊ทธ๋žฌ๋Š”๋ฐ

NAS ์ „์†ก์†๋„๊ฐ€ ํ›จ์”ฌ ๋А๋ ค์ง„๊ฒƒ ๊ฐ™๊ณ ....๋ฌด์Šจ ๋ฌธ์ œ์ธ๊ฐ€

0

์—ญ์‹œ ๊ฒŒ์ž„์—์„œ ํ•‘ ํŠ€๋Š”๊ฑด ๋ฒ”์ฃ„์ธ๋“ฏ

์ผํ•˜๋‹ค๊ฐ€ ๋™๋ฃŒ ํ•œ๋„˜์ด ์œ ๋ณ„๋‚˜๊ฒŒ ํ•‘ ํŠ€๋Š”๊ฑธ ์ˆ˜์ƒํ•˜๊ฒŒ ์—ฌ๊ธฐ๊ณ  ํšŒ์‚ฌ์— ๋ถˆ๋งŒ ์ œ๊ธฐํ–ˆ๋Š”๋ฐ

ํ•˜ํ•„์ด๋ฉด ๊ทธ๊ฒŒ ์œ„์žฅ์ทจ์—…ํ•œ ๋ถํ•œ ์š”์›์ด์—ˆ์Œ. ใ…‹ใ…‹

0
1

On Monday Surfer turns 3 and yesterday we released v0.5.0 featuring the long awaited analog rendering ๐ŸŽ‰

There are of course a bunch of other improvements that you can read more about in the change log

Massive thanks to Roman Popov for the analog drawing feature!

0
1
0
0
0
0
0
0
0

Top 5 improvements in Calendar 49:

1. Focus indicators were added in various places
2. Events are focusable with a keyboard
3. Year/month spin buttons are navigable with arrow keys
4. Calendar grids are skippable with Tab, and cells are wrapped via keyboard focus
5. Calendar list box now behaves like a check box

For screen readers: events and year/month spin buttons have proper semantics!

donate.gnome.org/

0
0
0
0

ๆคŽ่Šฑใกใ‚ƒใ‚“๏ผˆไปฃ็†ใกใ‚ƒใ‚“๏ผ‰ใฎไธ‰้ขๅ›ณใ‚’3Dใƒขใƒ‡ใƒชใƒณใ‚ฐ็”จใซๆใใชใŒใ‚‰ไธ€้ƒจใƒ‡ใ‚ถใ‚คใƒณใ—็›ดใ—ใฆใ‚‹

1
0

@hongminheeๆดช ๆฐ‘ๆ†™ (Hong Minhee) ์˜ค... ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ํ•œ๋ฒˆ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์‚ฌ์‹ค Vercel AI SDK๋Š” ์ฒซ์‚ฝ์„ ์ด๊ฑธ๋กœ ๋– ๋ฒ„๋ ค์„œ ์–ด์ฉ”์ˆ˜์—†์ด ์“ฐ๊ณ ์žˆ๋Š” ์ƒํƒœ์ž…๋‹ˆ๋‹ค. ๊ธ‰ํ•œ ๋ถˆ๋งŒ ๋„๊ณ  ์ข€๋” ๋‚˜์€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋กœ ๊ฐˆ์•„ํƒ€๋ ค๊ณ  ํ–ˆ์–ด์š”.

@hongminheeๆดช ๆฐ‘ๆ†™ (Hong Minhee) Vercel AI SDK์—์„œ ์ œ๊ฐ€ ๋ฌธ์ œ์ ์ด๋ผ๊ณ  ๋А๋‚€ ๋””์ž์ธ์„ ๊ทธ๋Œ€๋กœ ๊ฐ–๊ณ  ์žˆ๋„ค์š”. ์‚ฌ์‹ค ์ €๋„ ์•„์ง ์ถฉ๋ถ„ํžˆ ๊ณ ๋ฏผํ•ด๋ณด์ง„ ๋ชปํ–ˆ๊ณ  ๋ฐ˜๋Œ€ ์˜๊ฒฌ์€ ๋งค์šฐ ํ™˜์˜์ž…๋‹ˆ๋‹ค.

์ œ๊ฐ€ ๋ฌธ์ œ๋ผ๊ณ  ๋А๋‚€ ๋ถ€๋ถ„์€ Message ํƒ€์ž… ๋ฐ‘์— Part๊ฐ€ ์žˆ๋Š” ๊ฑด๋ฐ์š”. ๊ทธ๋Ÿฌ๋‹ˆ๊นŒ LLM์˜ ์‘๋‹ต์ด ํ”Œ๋žซํ•˜๊ฒŒ Message[]์ด ์•„๋‹ˆ๋ผ Message[].Part[]๊ฐ€ ๋ฉ๋‹ˆ๋‹ค. Part๋Š” Plain Text๊ฑฐ๋‚˜ Tool Call์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ์ด๊ฒŒ ๋ฉ”์‹œ์ง€๋ฅผ DB์— ์ €์žฅํ•˜๊ณ  Streaming UI๋ฅผ ๋งŒ๋“ค๋•Œ ๋ถˆํŽธํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ƒฅ Part๋ฅผ ์—†์• ๊ณ  Message๋งŒ ์žˆ์œผ๋ฉด ์ข‹๊ฒ ์–ด์š”.

์ฒ˜์Œ์— ์ €๋Ÿฐ์‹์˜ ๋””์ž์ธ์„ ํ•œ ๋™๊ธฐ๋ฅผ ์ถ”์ธกํ•ด๋ณด์ž๋ฉด, Message[]๋ฅผ User/Assitant/User/Assistant/... ์ด๋ ‡๊ฒŒ ๋ฒˆ๊ฐˆ์•„ ๋‚˜ํƒ€๋‚˜๋Š” ํ˜•ํƒœ๋ฅผ ๊ธฐ๋Œ€ํ•˜๊ณ , ๊ทธ๊ฑธ ๋งŒ์กฑ์‹œํ‚ค๋ ค๋ฉด Assistant/Assitant ์ด๋ ‡๊ฒŒ ์—ฐ๋‹ฌ์•„ ๋‚˜ํƒ€๋‚˜๋Š”๊ฑธ ํ”ผํ•ด์•ผํ•˜๋‹ˆ Part๋ฅผ ๋„์ž…ํ•œ๊ฒŒ ์•„๋‹Œ๊ฐ€ ์‹ถ์Šต๋‹ˆ๋‹ค. ๊ทผ๋ฐ ์‹ค์ œ๋ก  ์ € ๋ฒˆ๊ฐˆ์•„ ๋‚˜ํƒ€๋‚˜์•ผํ•œ๋‹ค๋Š” ์กฐ๊ฑด์ด ํƒ€์ž…์œผ๋กœ ๊ฐ•์ œ๋„ ์•ˆ๋˜๊ณ (์ด๊ฑด ์–ด๋ ค์šฐ๋‹ˆ OK) ๋Ÿฐํƒ€์ž„์—์„œ ๋ญ๋ผ๊ณ  ํ•˜์ง€๋„ ์•Š์•„์š”. ๊ทธ๋ฆฌ๊ณ  ์‹ค์ œ ์‚ฌ์šฉ์—์„œ ์—ฐ๋‹ฌ์•„ ๋‚˜ํƒ€๋‚˜๋Š”๊ฑธ ํ—ˆ์šฉํ•˜๋Š”๊ฒŒ ์˜คํžˆ๋ ค ์ž์—ฐ์Šค๋Ÿฝ์Šต๋‹ˆ๋‹ค.

๊ทธ๋ž˜์„œ ์ฒ˜์Œ์— ์ž ๊น ์ž˜๋ชป ์ƒ๊ฐํ•ด์„œ ๋‚˜์˜จ ๋””์ž์ธ์ด, ์‹ค์ œ๋ก  ์˜๋„ํ•œ ์ œ์•ฝ์„ ์ฃผ๊ณ ์žˆ์ง€๋„ ๋ชปํ•˜๊ณ  ๊ทธ๋ƒฅ ์“ฐ์ž„๋งŒ ๋ถˆํŽธํ•˜๊ฒŒ ๋งŒ๋“ค๊ณ  ์žˆ๋Š”๊ฑฐ ๊ฐ™์Šต๋‹ˆ๋‹ค.

2

ๅ…‰ใฎๅฝ“ใŸใ‚Šๅ…ทๅˆใŒใกใ‚‡ใ†ใฉใ„ใ„ๆ„Ÿใ˜ใซ
ใ“ใ‚Œใ ใ‘้ ญ้ƒจใฎ่ตคใŒใฏใฃใใ‚Š่ฆ‹ใˆใ‚‹ใฎใฏ็ใ—ใ„ใ‹ใ‚‚
โ€‹:blobcataww:โ€‹

1

ๅ…‰ใฎๅฝ“ใŸใ‚Šๅ…ทๅˆใŒใกใ‚‡ใ†ใฉใ„ใ„ๆ„Ÿใ˜ใซ
ใ“ใ‚Œใ ใ‘้ ญ้ƒจใฎ่ตคใŒใฏใฃใใ‚Š่ฆ‹ใˆใ‚‹ใฎใฏ็ใ—ใ„ใ‹ใ‚‚
โ€‹:blobcataww:โ€‹

1
์•„๋งˆ์ถ”์–ด ๋ฌด์„ ... ๋ง์ด ์•„๋งˆ์ถ”์–ด์ง€, ์•„๋ฌด๋ฆฌ ๋ด๋„ ์ด์ƒํ•œ ๋ฌด์„ ์ด์—์š”.
ใ‚ขใƒžใƒใƒฅใ‚ข็„ก็ทšโ€ฆใ‚ขใƒžใƒใƒฅใ‚ขใจใฏๅใฐใ‹ใ‚Šใงใ€ใฉใ†่ฆ‹ใฆใ‚‚ๅค‰ใช็„ก็ทšใงใ™ใ€‚โ€‹:blobcatgooglynotlikek:โ€‹
0
0

ไปŠๆ—ฅใฏ็พŽ่ก“้คจใซ่กŒใฃใฆใใŸใ‚“ใงใ™ใ‘ใฉใ€็พŽ่ก“้คจใงไฝœๅ“ใ‚’่ฆ‹ใฆๅ›žใ‚‹ใฎใฃใฆไฝ“ๅŠ›ใŒๅฟ…่ฆใชใ‚“ใ ใชใจๆ€ใ„ใพใ—ใŸโ€‹:blobcat_frustration:โ€‹
2ๆ™‚้–“ๅŠใใ‚‰ใ„็ซ‹ใฃใฆๆญฉใๅ›žใ‚‹ๅฟ…่ฆใŒใ‚ใ‚‹ใฎใงโ€ฆ

1
0

๋ณด์•ˆ ์—…๋ฐ์ดํŠธ: Hollo 0.6.19 ๋ฆด๋ฆฌ์Šค

Fedify์˜ HTML ํŒŒ์‹ฑ ์ฝ”๋“œ์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•œ Hollo 0.6.19๋ฅผ ๋ฆด๋ฆฌ์Šคํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ (CVE-2025-68475)์€ ReDoS(์ •๊ทœ ํ‘œํ˜„์‹ ์„œ๋น„์Šค ๊ฑฐ๋ถ€) ๋ฌธ์ œ๋กœ, ๊ณต๊ฒฉ์ž๊ฐ€ ์—ฐํ•ฉ ์ž‘์—… ์ค‘ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ HTML ์‘๋‹ต์„ ๋ณด๋‚ด ์„œ๋น„์Šค ์žฅ์• ๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋Š” ์ž‘์ง€๋งŒ(์•ฝ 170๋ฐ”์ดํŠธ), Node.js ์ด๋ฒคํŠธ ๋ฃจํ”„๋ฅผ ์žฅ์‹œ๊ฐ„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  Hollo ์šด์˜์ž๋ถ„๋“ค๊ป˜ ์ฆ‰์‹œ ๋ฒ„์ „ 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹ค ๊ฒƒ์„ ๊ฐ•๋ ฅํžˆ ๊ถŒ๊ณ ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

ํ•ญ๋ชฉ ์ƒ์„ธ
CVE CVE-2025-68475
์‹ฌ๊ฐ๋„ ๋†’์Œ (CVSS 7.5)
์กฐ์น˜ Hollo 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ

ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃใ‚ขใƒƒใƒ—ใƒ‡ใƒผใƒˆ: Hollo 0.6.19 ใƒชใƒชใƒผใ‚น

FedifyใฎHTMLใƒ‘ใƒผใ‚นใ‚ณใƒผใƒ‰ใซใŠใ‘ใ‚‹ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃ่„†ๅผฑๆ€งใซๅฏพๅฟœใ—ใŸHollo 0.6.19ใ‚’ใƒชใƒชใƒผใ‚นใ—ใพใ—ใŸใ€‚

ใ“ใฎ่„†ๅผฑๆ€ง (CVE-2025-68475) ใฏ ReDoS (ๆญฃ่ฆ่กจ็พใซใ‚ˆใ‚‹ใ‚ตใƒผใƒ“ใ‚นๆ‹’ๅฆ) ใฎๅ•้กŒใงใ‚ใ‚Šใ€ๆ”ปๆ’ƒ่€…ใŒใƒ•ใ‚งใƒ‡ใƒฌใƒผใ‚ทใƒงใƒณๆ“ไฝœไธญใซ็‰นๅˆฅใซ็ดฐๅทฅใ•ใ‚ŒใŸHTMLใƒฌใ‚นใƒใƒณใ‚นใ‚’้€ไฟกใ™ใ‚‹ใ“ใจใงใ€ใ‚ตใƒผใƒ“ใ‚นๅœๆญขใ‚’ๅผ•ใ่ตทใ“ใ™ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใพใ™ใ€‚ๆ‚ชๆ„ใฎใ‚ใ‚‹ใƒšใ‚คใƒญใƒผใƒ‰ใฏๅฐใ•ใ„ (็ด„170ใƒใ‚คใƒˆ) ใงใ™ใŒใ€Node.jsใฎใ‚คใƒ™ใƒณใƒˆใƒซใƒผใƒ—ใ‚’้•ทๆ™‚้–“ใƒ–ใƒญใƒƒใ‚ฏใ™ใ‚‹ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใพใ™ใ€‚

ใ™ในใฆใฎHollo้‹ๅ–ถ่€…ใฎ็š†ๆง˜ใซใฏใ€็›ดใกใซใƒใƒผใ‚ธใƒงใƒณ 0.6.19 ใธใฎใ‚ขใƒƒใƒ—ใ‚ฐใƒฌใƒผใƒ‰ใ‚’ๅผทใใŠๅ‹งใ‚ใ—ใพใ™ใ€‚

้ …็›ฎ ่ฉณ็ดฐ
CVE CVE-2025-68475
ๆทฑๅˆปๅบฆ ้ซ˜ (CVSS 7.5)
ๅฏพๅฟœ Hollo 0.6.19 ใซใ‚ขใƒƒใƒ—ใ‚ฐใƒฌใƒผใƒ‰

1
1
1

Security Update: Hollo 0.6.19 Released

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

Field Details
CVE CVE-2025-68475
Severity High (CVSS 7.5)
Action Upgrade to Hollo 0.6.19

๋ณด์•ˆ ์—…๋ฐ์ดํŠธ: Hollo 0.6.19 ๋ฆด๋ฆฌ์Šค

Fedify์˜ HTML ํŒŒ์‹ฑ ์ฝ”๋“œ์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•œ Hollo 0.6.19๋ฅผ ๋ฆด๋ฆฌ์Šคํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ (CVE-2025-68475)์€ ReDoS(์ •๊ทœ ํ‘œํ˜„์‹ ์„œ๋น„์Šค ๊ฑฐ๋ถ€) ๋ฌธ์ œ๋กœ, ๊ณต๊ฒฉ์ž๊ฐ€ ์—ฐํ•ฉ ์ž‘์—… ์ค‘ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ HTML ์‘๋‹ต์„ ๋ณด๋‚ด ์„œ๋น„์Šค ์žฅ์• ๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋Š” ์ž‘์ง€๋งŒ(์•ฝ 170๋ฐ”์ดํŠธ), Node.js ์ด๋ฒคํŠธ ๋ฃจํ”„๋ฅผ ์žฅ์‹œ๊ฐ„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  Hollo ์šด์˜์ž๋ถ„๋“ค๊ป˜ ์ฆ‰์‹œ ๋ฒ„์ „ 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹ค ๊ฒƒ์„ ๊ฐ•๋ ฅํžˆ ๊ถŒ๊ณ ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

ํ•ญ๋ชฉ ์ƒ์„ธ
CVE CVE-2025-68475
์‹ฌ๊ฐ๋„ ๋†’์Œ (CVSS 7.5)
์กฐ์น˜ Hollo 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ

1
0
0

Security Update: Hollo 0.6.19 Released

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

Field Details
CVE CVE-2025-68475
Severity High (CVSS 7.5)
Action Upgrade to Hollo 0.6.19

0
0

๋ณด์•ˆ ์—…๋ฐ์ดํŠธ: Hollo 0.6.19 ๋ฆด๋ฆฌ์Šค

Fedify์˜ HTML ํŒŒ์‹ฑ ์ฝ”๋“œ์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•œ Hollo 0.6.19๋ฅผ ๋ฆด๋ฆฌ์Šคํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ (CVE-2025-68475)์€ ReDoS(์ •๊ทœ ํ‘œํ˜„์‹ ์„œ๋น„์Šค ๊ฑฐ๋ถ€) ๋ฌธ์ œ๋กœ, ๊ณต๊ฒฉ์ž๊ฐ€ ์—ฐํ•ฉ ์ž‘์—… ์ค‘ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ HTML ์‘๋‹ต์„ ๋ณด๋‚ด ์„œ๋น„์Šค ์žฅ์• ๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋Š” ์ž‘์ง€๋งŒ(์•ฝ 170๋ฐ”์ดํŠธ), Node.js ์ด๋ฒคํŠธ ๋ฃจํ”„๋ฅผ ์žฅ์‹œ๊ฐ„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  Hollo ์šด์˜์ž๋ถ„๋“ค๊ป˜ ์ฆ‰์‹œ ๋ฒ„์ „ 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹ค ๊ฒƒ์„ ๊ฐ•๋ ฅํžˆ ๊ถŒ๊ณ ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

ํ•ญ๋ชฉ ์ƒ์„ธ
CVE CVE-2025-68475
์‹ฌ๊ฐ๋„ ๋†’์Œ (CVSS 7.5)
์กฐ์น˜ Hollo 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ

ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃใ‚ขใƒƒใƒ—ใƒ‡ใƒผใƒˆ: Hollo 0.6.19 ใƒชใƒชใƒผใ‚น

FedifyใฎHTMLใƒ‘ใƒผใ‚นใ‚ณใƒผใƒ‰ใซใŠใ‘ใ‚‹ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃ่„†ๅผฑๆ€งใซๅฏพๅฟœใ—ใŸHollo 0.6.19ใ‚’ใƒชใƒชใƒผใ‚นใ—ใพใ—ใŸใ€‚

ใ“ใฎ่„†ๅผฑๆ€ง (CVE-2025-68475) ใฏ ReDoS (ๆญฃ่ฆ่กจ็พใซใ‚ˆใ‚‹ใ‚ตใƒผใƒ“ใ‚นๆ‹’ๅฆ) ใฎๅ•้กŒใงใ‚ใ‚Šใ€ๆ”ปๆ’ƒ่€…ใŒใƒ•ใ‚งใƒ‡ใƒฌใƒผใ‚ทใƒงใƒณๆ“ไฝœไธญใซ็‰นๅˆฅใซ็ดฐๅทฅใ•ใ‚ŒใŸHTMLใƒฌใ‚นใƒใƒณใ‚นใ‚’้€ไฟกใ™ใ‚‹ใ“ใจใงใ€ใ‚ตใƒผใƒ“ใ‚นๅœๆญขใ‚’ๅผ•ใ่ตทใ“ใ™ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใพใ™ใ€‚ๆ‚ชๆ„ใฎใ‚ใ‚‹ใƒšใ‚คใƒญใƒผใƒ‰ใฏๅฐใ•ใ„ (็ด„170ใƒใ‚คใƒˆ) ใงใ™ใŒใ€Node.jsใฎใ‚คใƒ™ใƒณใƒˆใƒซใƒผใƒ—ใ‚’้•ทๆ™‚้–“ใƒ–ใƒญใƒƒใ‚ฏใ™ใ‚‹ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใพใ™ใ€‚

ใ™ในใฆใฎHollo้‹ๅ–ถ่€…ใฎ็š†ๆง˜ใซใฏใ€็›ดใกใซใƒใƒผใ‚ธใƒงใƒณ 0.6.19 ใธใฎใ‚ขใƒƒใƒ—ใ‚ฐใƒฌใƒผใƒ‰ใ‚’ๅผทใใŠๅ‹งใ‚ใ—ใพใ™ใ€‚

้ …็›ฎ ่ฉณ็ดฐ
CVE CVE-2025-68475
ๆทฑๅˆปๅบฆ ้ซ˜ (CVSS 7.5)
ๅฏพๅฟœ Hollo 0.6.19 ใซใ‚ขใƒƒใƒ—ใ‚ฐใƒฌใƒผใƒ‰

1

Security Update: Hollo 0.6.19 Released

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

Field Details
CVE CVE-2025-68475
Severity High (CVSS 7.5)
Action Upgrade to Hollo 0.6.19

๋ณด์•ˆ ์—…๋ฐ์ดํŠธ: Hollo 0.6.19 ๋ฆด๋ฆฌ์Šค

Fedify์˜ HTML ํŒŒ์‹ฑ ์ฝ”๋“œ์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•œ Hollo 0.6.19๋ฅผ ๋ฆด๋ฆฌ์Šคํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ (CVE-2025-68475)์€ ReDoS(์ •๊ทœ ํ‘œํ˜„์‹ ์„œ๋น„์Šค ๊ฑฐ๋ถ€) ๋ฌธ์ œ๋กœ, ๊ณต๊ฒฉ์ž๊ฐ€ ์—ฐํ•ฉ ์ž‘์—… ์ค‘ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ HTML ์‘๋‹ต์„ ๋ณด๋‚ด ์„œ๋น„์Šค ์žฅ์• ๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋Š” ์ž‘์ง€๋งŒ(์•ฝ 170๋ฐ”์ดํŠธ), Node.js ์ด๋ฒคํŠธ ๋ฃจํ”„๋ฅผ ์žฅ์‹œ๊ฐ„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  Hollo ์šด์˜์ž๋ถ„๋“ค๊ป˜ ์ฆ‰์‹œ ๋ฒ„์ „ 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹ค ๊ฒƒ์„ ๊ฐ•๋ ฅํžˆ ๊ถŒ๊ณ ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

ํ•ญ๋ชฉ ์ƒ์„ธ
CVE CVE-2025-68475
์‹ฌ๊ฐ๋„ ๋†’์Œ (CVSS 7.5)
์กฐ์น˜ Hollo 0.6.19๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ

1

Security Update: Hollo 0.6.19 Released

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

Field Details
CVE CVE-2025-68475
Severity High (CVSS 7.5)
Action Upgrade to Hollo 0.6.19

0

Security Update: Hollo 0.6.19 Released

We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

Field Details
CVE CVE-2025-68475
Severity High (CVSS 7.5)
Action Upgrade to Hollo 0.6.19

0
0
0
0

ใ“ใ‚Œใฏๅ…ฅๆ›ฝใซๆฅใฆ้ฃฒใ‚€ในใ—๏ผ
ใจใชใ‚‹ใ‚‚ใฎใฎไธ€ใคใฎใ‚ˆใ†ใซๆ„Ÿใ˜ใŸใ€‚
็ด™ใ‚ณใƒƒใƒ—ใƒ‘ใƒƒใ‚ฑใƒผใ‚ธใ‚‚ใ†ๅฐ‘ใ—ใฉใ†ใซใ‹ใชใ‚‰ใ‚“ใ‹ใชใ‚ใ€‚
ๅ €ๅ…ผใฎ็Ÿณ็”ฐๅœ’ใ•ใ‚“ใฎๆŠน่Œถใ ใใ†ใ€‚
#ๅคงๅžฃๆ›ธๅบ—ๅ…ฅๆ›ฝๅบ—

May be an image of tea, smoothie and text that says 'ๅ…ฅๆ›พใฎๅคงๅžฃๆ›ธๅบ—ใฎๆŠน่Œถใƒฉใƒ†ใŒ ๅฎ‡ๆฒปๆŠน่Œถใƒฉใƒ†ใ‹ใ‚‰ ็‹ญๅฑฑๆŠน่Œถใƒฉใƒ†ใซใชใฃใฆใ„ใŸ ๆ ผๆฎตใซ็พŽๅ‘ณใใชใฃใฆใ‚‹...๏ผ ๏ผˆใ€Œใ•ใ‚„ใพใฃใกใ‚ƒใ€ ใ€Œใ•ใ‚„ใพใฃใกใ‚„ใ€ใฃใฆ็™บ้Ÿณใ—ใใ†ใซใชใฃใŸ ใฃใฆ็™บ้Ÿณใ—ใใ†ใซใชใฃใŸ๏ผ‰'
0

7ๅนดไปฅไธŠๅ‰ใฎ่จ˜ไบ‹ใ ใ‘ใฉใ€ใ€Œ :vivaldi_red: ใฏ็ตๅฑ€ Chrome/Chromium ใ ใ‹ใ‚‰ใ€ใจใ„ใ†่ฉฑใŒๆœ€่ฟ‘ Firefox ใฎใƒใ‚ฟใƒใ‚ฟใฎ็ตกใฟใงๅ‡บใฆใใ‚‹ใฎใ‚’็›ฎใซใ—ใฆใคใ„ใ“ใฎ่จ˜ไบ‹ใ‚’ๆ€ใ„ๅ‡บใ—ใŸ

Vivaldiใƒ–ใƒฉใ‚ฆใ‚ถใฏChromiumใง้–‹็™บใ—ใฆใ„ใพใ™ใŒใ€Chromeใงใฏใ‚ใ‚Šใพใ›ใ‚“ | Vivaldi Browser
vivaldi.com/ja/blog/vivaldi-di

0

Driving myself crazy trying to remember the name of a social media reader project. Things I (think I) remember about it:

1. Conceptually, it was basically an RSS reader but had the ability to aggregate social media sites that didn't use RSS.

2. It ran as a browser plugin, not a standalone app or website.

3. It had a very "a trans catgirl wrote this" name and aesthetic, that did not make it obvious what the project actually was. Think like "pink robot kitten explosion" except, like. Not that, obviously.

4. I've seen the engine (?) of it repackaged as a plugin/extension for other feed reader apps.

And yes I am aware the above sounds like a fever dream but I
swear to gods this was (is?) real and did (does?) exist and, fedi, if there's one place on the internet that may be able to remember this for me wholesale, I believe it to be you. Halp?

Edit: Found it! Knew you'd come through, fedi!

0
0
1
0

speaking of shoulds, I've been occasionally tempted by the prospect of buying a Playdate. i'm sure some of you have been paying attention to it more than I am - is it a good gimmicky small game handheld?

0
1
0

Q: ๋ˆ„์นด-์ฝœ๋ผ์— ํ•œ ํ‘œ๋ฅผ ๋˜์ง‘๋‹ˆ๋‹ค #neo_quesdon

A: ์ฝœ๋ผ๊ฐ€ ๋ฐค์—๋„ ๋น›๋‚˜์„œ ์ฐธ ๋ณด๊ธฐ ์ข‹์•„์š”
https://neo-quesdon.serafuku.moe/main/user/@nulta@mi.rerac.dev/cmje8eu0d46z5o60jiy0inlw5

0
1
0
1