Skip to main content

Vendor/product archive

joinmastodon / mastodon CVEs

Beta · best-effort

42 CVEs tagged to joinmastodon / mastodon6 Critical, 10 High, 23 Medium, 3 Low, 0 Unrated.

CVE-2026-41259

Published Apr 23, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail dom…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33869

Published Mar 27, 2026

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker tha…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33868

Published Mar 27, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) e…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27477

Published Feb 24, 2026

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27468

Published Feb 24, 2026

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25540

Published Feb 4, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23964

Published Jan 22, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscr…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-23963

Published Jan 22, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-23962

Published Jan 22, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-23961

Published Jan 22, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some lo…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-22246

Published Jan 8, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationsh…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-22245

Published Jan 8, 2026

Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, ha…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-67500

Published Dec 10, 2025

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 throug…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62605

Published Oct 21, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is po…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62176

Published Oct 13, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public ti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62175

Published Oct 13, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62174

Published Oct 13, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password v…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-54879

Published Aug 6, 2025

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27399

Published Feb 27, 2025

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (local…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27157

Published Feb 27, 2025

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Withou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49952

Published Nov 18, 2024

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34535

Published Oct 3, 2024

In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37903

Published Jul 5, 2024

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can ex…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25623

Published Feb 19, 2024

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't ch…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25619

Published Feb 14, 2024

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Toke…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2