Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.5.11之前版本、4.4.18之前版本和4.3.24之前版本存在异常处理不当漏洞,该漏洞源于数学清理器缺少异常处理,导致未捕获异常,畸形<math>节点可能导致整个服务器或目标用户服务拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47389 | 8.6 HIGH | Mastodon: SSRF protection bypass on older Ruby versions |
| CVE-2026-48028 | 6.5 MEDIUM | Mastodon: Removal of integrity-protected JSON entries from signed activities |
| CVE-2026-50128 | 5.3 MEDIUM | Mastodon: Spoofing of attribution domains |
| CVE-2026-46349 | 5.3 MEDIUM | Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-46348 | Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) |
No comments yet