VYPR

Bitnami package

mastodon

pkg:bitnami/mastodon

Vulnerabilities (52)

  • CVE-2026-59825HigAug 18, 2026
    affected < 4.4.19fixed 4.4.19

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=tru

  • CVE-2026-72916MedAug 10, 2026
    affected < 4.4.21fixed 4.4.21

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses but did not recognize IPv4-compatible IPv6

  • CVE-2026-72915HigAug 10, 2026
    affected >= 4.6.0, < 4.6.4fixed 4.6.4

    Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about ano

  • CVE-2026-72914HigAug 10, 2026
    affected < 4.4.21fixed 4.4.21

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked authorization only a

  • CVE-2026-50129HigJun 24, 2026
    affected < 4.3.24fixed 4.3.24

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed nodes can result in a DoS of a w

  • CVE-2026-50128MedJun 24, 2026
    affected >= 4.3.0, < 4.4.18fixed 4.4.18

    Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their articles. To prevent false attribution claims, Mastodon uses the attributionDomains JSON-LD term, however

  • CVE-2026-48028MedJun 24, 2026
    affected < 4.3.23fixed 4.3.23

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allow

  • CVE-2026-47389HigJun 24, 2026
    affected >= 4.5.0, < 4.5.10fixed 4.5.10

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? returns false for IPv4-mapped IPv6 addresses (::ffff:a.b.c.d) corresponding to some priva

  • CVE-2026-46349MedJun 24, 2026
    affected >= 4.5.0, < 4.5.10fixed 4.5.10

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allow

  • CVE-2026-46348HigJun 24, 2026
    affected >= 4.5.0, < 4.5.10fixed 4.5.10

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was lacking an IP address range that can be used to reach local IP addresses. An attacker can use an IP address in the affecte

  • CVE-2026-47777HigJun 15, 2026
    affected >= nightly.2026-03-10.0, < 4.6.0fixed 4.6.0

    Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could f

  • CVE-2026-41259HigApr 23, 2026
    affected < 4.3.22fixed 4.3.22

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that a

  • CVE-2026-33869MedMar 27, 2026
    affected >= 4.4.0, < 4.4.15fixed 4.4.15

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on th

  • CVE-2026-33868MedMar 27, 2026
    affected < 4.3.21fixed 4.3.21

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can cr

  • CVE-2026-27477MedFeb 24, 2026
    affected >= 4.4.0, < 4.4.14fixed 4.4.14

    Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with an attacker-chosen `base_url`

  • CVE-2026-27468HigFeb 24, 2026
    affected >= 4.4.0, < 4.4.14fixed 4.4.14

    Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to

  • CVE-2026-25540MedFeb 4, 2026
    affected < 4.5.6fixed 4.5.6

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinned posts and featured hashtags

  • CVE-2026-23964MedJan 22, 2026
    affected < 4.3.18fixed 4.3.18

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessin

  • CVE-2026-23963MedJan 22, 2026
    affected < 4.3.18fixed 4.3.18

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as

  • CVE-2026-23962HigJan 22, 2026
    affected < 4.3.18fixed 4.3.18

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, gr

Page 1 of 3