VYPR

Bitnami package

mastodon

pkg:bitnami/mastodon

Vulnerabilities (52)

  • CVE-2026-23961MedJan 22, 2026
    affected < 4.3.18fixed 4.3.18

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Fur

  • CVE-2026-22246MedJan 8, 2026
    affected < 4.3.17fixed 4.3.17

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of seve

  • CVE-2026-22245HigJan 8, 2026
    affected < 4.2.29fixed 4.2.29

    Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_

  • CVE-2025-67500LowDec 10, 2025
    affected < 4.2.28fixed 4.2.28

    Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking whether a given status exists by se

  • CVE-2025-62605MedOct 21, 2025
    affected >= 4.4.0, < 4.4.8fixed 4.4.8

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2.

  • CVE-2025-62176MedOct 13, 2025
    affected < 4.2.27fixed 4.2.27

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses

  • CVE-2025-62175MedOct 13, 2025
    affected < 4.2.27fixed 4.2.27

    Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receivin

  • CVE-2025-62174LowOct 13, 2025
    affected < 4.2.27fixed 4.2.27

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions a

  • CVE-2025-54879MedAug 6, 2025
    affected >= 3.1.5, < 4.2.24fixed 4.2.24

    Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical configuratio

  • CVE-2025-27399MedFeb 27, 2025
    affected < 4.3.4fixed 4.3.4

    Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reason

  • CVE-2025-27157MedFeb 27, 2025
    affected >= 4.2.0, < 4.3.4fixed 4.3.4

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses

  • CVE-2023-49952HigNov 18, 2024
    affected >= 4.1.0, < 4.1.17fixed 4.1.17

    Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

  • CVE-2024-34535MedOct 3, 2024
    affected < 4.2.9fixed 4.2.9

    In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

  • CVE-2024-37903HigJul 5, 2024
    affected >= 2.6.0, < 4.1.18fixed 4.1.18

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining

  • CVE-2024-25623HigFeb 19, 2024
    affected < 3.5.19fixed 3.5.19

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Stream

  • CVE-2024-25619LowFeb 14, 2024
    affected < 4.2.6fixed 4.2.6

    Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application

  • CVE-2024-25618MedFeb 14, 2024
    affected < 3.5.18fixed 3.5.18

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a possible account takeover if the

  • CVE-2024-23832CriFeb 1, 2024
    affected < 3.5.17fixed 3.5.17

    Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to

  • CVE-2023-42452MedSep 19, 2023
    affected >= 4.0.0, < 4.0.10fixed 4.0.10

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing un

  • CVE-2023-42451HigSep 19, 2023
    affected < 3.5.14fixed 3.5.14

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.