VYPR
High severity7.5NVD Advisory· Published Apr 23, 2026· Updated Jun 17, 2026

CVE-2026-41259

CVE-2026-41259

Description

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Mastodon/Mastodon2 versions
    cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*range: <4.3.22
    • (no CPE)range: <4.5.9, <4.4.16, <4.3.22
  • osv-coords
    Range: < 4.3.22

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.