Mastodon是Mastodon组织的一款去中心化社交网络服务器软件。 Mastodon 4.6.0-beta.1版本至4.6.4之前版本存在信息泄露漏洞,该漏洞源于控制器使用通用collection策略而非admin collection策略命名空间,可能导致已登录本地用户访问其他用户的个人身份信息,包括当前电子邮件地址和上次使用的IP地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72914 | 7.5 HIGH | Mastodon: Exhausting data by an unauthenticated request to the admin retention API |
| CVE-2026-72916 | 6.3 MEDIUM | Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses |
No comments yet