VYPR
Medium severity5.3NVD Advisory· Published Feb 27, 2025· Updated Jun 17, 2026

CVE-2025-27399

CVE-2025-27399

Description

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 fix the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Mastodon/Mastodon3 versions
    cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*range: <4.1.23
    • (no CPE)range: <4.1.23, <4.2.16, <4.3.4
    • (no CPE)range: < 4.1.23
  • osv-coords
    Range: < 4.3.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.