Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.5.10之前版本、4.4.17之前版本和4.3.23之前版本存在加密问题漏洞,该漏洞源于对具有链式数据签名的传入活动规范化处理不足,可能导致攻击者能够重新排列来自第三方的有效签名JSON-LD活动,使其以不同方式处理。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47389 | 8.6 HIGH | Mastodon: SSRF protection bypass on older Ruby versions |
| CVE-2026-50129 | 7.5 HIGH | Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER |
| CVE-2026-48028 | 6.5 MEDIUM | Mastodon: Removal of integrity-protected JSON entries from signed activities |
| CVE-2026-50128 | 5.3 MEDIUM | Mastodon: Spoofing of attribution domains |
| CVE-2026-46348 | Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) |
No comments yet