VYPR

Mastodon

by Mastodon

Source repositories

CVEs (53)

  • CVE-2026-46349MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing,…

  • CVE-2026-33869MedMar 27, 2026
    risk 0.24cvss 4.8epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on…

  • CVE-2026-33868MedMar 27, 2026
    risk 0.21cvss 4.3epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can…

  • CVE-2023-36460CriJul 6, 2023
    risk 0.03cvss 9.9epss 0.40

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any…

  • CVE-2026-27477MedFeb 24, 2026
    risk 0.00cvss 5.9epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with an attacker-chosen…

  • CVE-2026-27468HigFeb 24, 2026
    risk 0.00cvss 8.2epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or…

  • CVE-2026-22246MedJan 8, 2026
    risk 0.00cvss 6.5epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of…

  • CVE-2026-22245HigJan 8, 2026
    risk 0.00cvss 7.5epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in…

  • CVE-2025-67500LowDec 10, 2025
    risk 0.00cvss 3.7epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking whether a given status exists by…

  • CVE-2025-62605MedOct 21, 2025
    risk 0.00cvss 4.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and…

  • CVE-2025-62176MedOct 13, 2025
    risk 0.00cvss 4.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses…

  • CVE-2025-62175MedOct 13, 2025
    risk 0.00cvss 4.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue…

  • CVE-2025-62174LowOct 13, 2025
    risk 0.00cvss 3.5epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions…

  • CVE-2025-54879MedAug 6, 2025
    risk 0.00cvss 5.3epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical…

  • CVE-2025-27399MedFeb 27, 2025
    risk 0.00cvss 5.3epss 0.00

    Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block…

  • CVE-2025-27157MedFeb 27, 2025
    risk 0.00cvss 5.3epss 0.00

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary…

  • CVE-2024-37903HigJul 5, 2024
    risk 0.00cvss 8.2epss 0.01

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining…

  • CVE-2024-25623HigFeb 19, 2024
    risk 0.00cvss 8.5epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity…

  • CVE-2024-25619LowFeb 14, 2024
    risk 0.00cvss 3.1epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application…

  • CVE-2024-25618MedFeb 14, 2024
    risk 0.00cvss 4.2epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a possible account takeover if…