Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-47389— Mastodon: SSRF protection bypass on older Ruby versions

Quick assessment

Affected
mastodon mastodon
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.5.10之前版本、4.4.17之前版本和4.3.23之前版本存在安全漏洞,该漏洞源于使用Ruby 3.4之前版本时,PrivateAddressCheck.private_address?函数对IPv4映射的IPv6地址验证错误,可能导致控制DNS的攻击者通过发布包含映射地址的AAAA记录,使Mastodon发出的出站HTTP请求建立到内部IPv4地址的TCP连接,包括回环地址和云元数据端点,从而导致服务端请求

CVSS 8.6 · High EPSS 0.39% · P31

Affected Version Matrix 1

VendorProduct Version RangeStatus
mastodon mastodon >= 4.5.0-beta.1, < 4.5.10 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-47389

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mastodon: SSRF protection bypass on older Ruby versions
Source: CVE Program / CVE List V5
Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? returns false for IPv4-mapped IPv6 addresses (::ffff:a.b.c.d) corresponding to some private IPv4 addresses, depending on Ruby version, this can include loopback, RFC1918 private networks, and link-local space. An attacker who controls DNS for any domain can publish an AAAA record with such a mapped address; any outbound HTTP fetch Mastodon performs against that hostname then opens a real TCP connection to the underlying IPv4 address, including 127.0.0.1 and cloud-metadata endpoints such as 169.254.169.254. This vulnerability is fixed in 4.5.10, 4.4.17, and 4.3.23.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5
Vulnerability Title
Mastodon 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.5.10之前版本、4.4.17之前版本和4.3.23之前版本存在安全漏洞,该漏洞源于使用Ruby 3.4之前版本时,PrivateAddressCheck.private_address?函数对IPv4映射的IPv6地址验证错误,可能导致控制DNS的攻击者通过发布包含映射地址的AAAA记录,使Mastodon发出的出站HTTP请求建立到内部IPv4地址的TCP连接,包括回环地址和云元数据端点,从而导致服务端请求
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
mastodon mastodon >= 4.5.0-beta.1, < 4.5.10 -

II. Public POCs for CVE-2026-47389

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-47389

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-47389 (1)

Same Patch Batch · mastodon · 2026-06-24 · 6 CVEs total

CVE-2026-50129 7.5 HIGH Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER
CVE-2026-48028 6.5 MEDIUM Mastodon: Removal of integrity-protected JSON entries from signed activities
CVE-2026-50128 5.3 MEDIUM Mastodon: Spoofing of attribution domains
CVE-2026-46349 5.3 MEDIUM Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-46348 Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)

IV. Related Vulnerabilities

V. Comments for CVE-2026-47389

No comments yet


Leave a comment