Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mastodon — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in mastodon, with AI-generated Chinese analysis, references, and POCs.

This page aggregates historical vulnerability advisories for the Mastodon social network platform, focusing on specific software components and general security weakness classes associated with the product. The collection documents reported security flaws, including remote code execution, cross-site scripting, and access control issues, spanning the period from initial open-source releases through recent maintenance patches. Readers can use this index to track vendor-issued security bulletins, analyze recurring weakness patterns, and review the complete vulnerability history for the Mastodon codebase. The entries are organized chronologically and by Common Weakness Enumeration identifiers, allowing security teams to identify trends and assess risk exposure across different versions of the application. No individual vulnerability identifiers are highlighted; instead, the focus remains on categorizing and correlating the defects to support broader security posture analysis.

Vendor: mastodon

CVE ID Title CVSS Severity Published
CVE-2026-59825 Mastodon: Unwanted deactivation of SSL/TLS certificate verification CWE-295 7.4 High 2026-08-18
CVE-2026-72916 Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses CWE-918 6.3 Medium 2026-08-10
CVE-2026-72915 Mastodon: Personally-identifying information disclosure due to incorrect access control validation CWE-200 7.5 High 2026-08-10
CVE-2026-72914 Mastodon: Exhausting data by an unauthenticated request to the admin retention API CWE-405 7.5 High 2026-08-10
CVE-2026-50129 Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER CWE-248 7.5 High 2026-06-24
CVE-2026-50128 Mastodon: Spoofing of attribution domains CWE-354 5.3 Medium 2026-06-24
CVE-2026-48028 Mastodon: Removal of integrity-protected JSON entries from signed activities CWE-354 6.5 Medium 2026-06-24
CVE-2026-47389 Mastodon: SSRF protection bypass on older Ruby versions CWE-184 8.6 High 2026-06-24
CVE-2026-46349 Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring CWE-347 5.3 Medium 2026-06-24
CVE-2026-46348 Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) CWE-918 - - 2026-06-24
CVE-2026-47777 Mastodon has a consent-check bypass in its remote Collections CWE-345 7.5 High 2026-06-15
CVE-2026-41259 Mastodon: Insufficient verification of email addresses CWE-841 4.3AI Medium AI 2026-04-23
CVE-2026-33869 Mastodon has a denial of service for quote authorization CWE-863 4.8 Medium 2026-03-27
CVE-2026-33868 Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>' CWE-601 4.3 Medium 2026-03-27
CVE-2026-27477 Mastodon has SSRF via unvalidated FASP Provider base_url CWE-918 6.5 - 2026-02-24
CVE-2026-27468 Mastodon may allow unconfirmed FASP to make subscriptions CWE-862 6.7 - 2026-02-24
CVE-2026-25540 Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`) CWE-524 6.5 Medium 2026-02-04
CVE-2026-23964 Mastodon has insufficient access control to push notification settings CWE-863 6.5 Medium 2026-01-22
CVE-2026-23963 Mastodon missing length limits on list names, filter names, and filter keywords CWE-770 4.3 Medium 2026-01-22
CVE-2026-23962 Mastodon vulnerable to Denial of Service from a single post (client/server) CWE-770 7.5 High 2026-01-22
CVE-2026-23961 Mastodon may allow a remote suspension bypass CWE-863 5.3 Medium 2026-01-22
CVE-2026-22246 Local Mastodon users can enumerate and access severed relationships of every other local user CWE-201 6.5 Medium 2026-01-08
CVE-2026-22245 Mastodon has SSRF Protection bypass CWE-918 9.4 - 2026-01-08
CVE-2025-67500 Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration CWE-204 3.7 Low 2025-12-09
CVE-2025-62605 Mastodon quotes control can be bypassed CWE-754 4.3 Medium 2025-10-21
CVE-2025-62176 Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channels CWE-280 4.3 Medium 2025-10-13
CVE-2025-62175 Mastodon streaming API fails to disconnect disabled and suspended users CWE-273 4.3 Medium 2025-10-13
CVE-2025-62174 Mastodon allows continued access after password reset via CLI CWE-613 3.5 Low 2025-10-13
CVE-2025-54879 Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails CWE-770 5.3 Medium 2025-08-05
CVE-2025-27399 Mastodon's domain blocks & rationales ignore user approval when visibility set as "users" CWE-200 5.3 Medium 2025-02-27

All 44 known CVE vulnerabilities affecting mastodon with full Chinese analysis, references, and POCs where available.