Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mastodon — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting mastodon. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mastodon is an open-source, self-hosted microblogging platform designed to decentralize social networking through the ActivityPub protocol. Its architecture allows users to operate independent instances that interoperate within a federated network, prioritizing user control over centralized corporate data silos. Historically, security audits have identified approximately 35 Common Vulnerabilities and Exposures (CVEs) within the codebase. These flaws predominantly involve server-side request forgery, cross-site scripting, and improper access control mechanisms, often stemming from complex interactions between the Ruby on Rails backend and the PostgreSQL database. While no catastrophic data breaches have defined its history, the platform’s decentralized nature means security incidents are typically isolated to specific instances rather than affecting the entire network. Recent patches have focused on hardening authentication flows and mitigating injection vulnerabilities, reflecting the ongoing challenges of maintaining security in a distributed, community-driven software ecosystem.

Top products by mastodon: mastodon mastodon/mastodon
CVE ID Title CVSS Severity Published
CVE-2026-59825 Mastodon: Unwanted deactivation of SSL/TLS certificate verification — mastodon CWE-295 7.4 High 2026-08-18
CVE-2026-72916 Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses — mastodon CWE-918 6.3 Medium 2026-08-10
CVE-2026-72915 Mastodon: Personally-identifying information disclosure due to incorrect access control validation — mastodon CWE-200 7.5 High 2026-08-10
CVE-2026-72914 Mastodon: Exhausting data by an unauthenticated request to the admin retention API — mastodon CWE-405 7.5 High 2026-08-10
CVE-2026-50129 Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER — mastodon CWE-248 7.5 High 2026-06-24
CVE-2026-50128 Mastodon: Spoofing of attribution domains — mastodon CWE-354 5.3 Medium 2026-06-24
CVE-2026-48028 Mastodon: Removal of integrity-protected JSON entries from signed activities — mastodon CWE-354 6.5 Medium 2026-06-24
CVE-2026-47389 Mastodon: SSRF protection bypass on older Ruby versions — mastodon CWE-184 8.6 High 2026-06-24
CVE-2026-46349 Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring — mastodon CWE-347 5.3 Medium 2026-06-24
CVE-2026-46348 Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) — mastodon CWE-918 - - 2026-06-24
CVE-2026-47777 Mastodon has a consent-check bypass in its remote Collections — mastodon CWE-345 7.5 High 2026-06-15
CVE-2026-41259 Mastodon: Insufficient verification of email addresses — mastodon CWE-841 4.3AI Medium AI 2026-04-23
CVE-2026-33869 Mastodon has a denial of service for quote authorization — mastodon CWE-863 4.8 Medium 2026-03-27
CVE-2026-33868 Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>' — mastodon CWE-601 4.3 Medium 2026-03-27
CVE-2026-27477 Mastodon has SSRF via unvalidated FASP Provider base_url — mastodon CWE-918 6.5 - 2026-02-24
CVE-2026-27468 Mastodon may allow unconfirmed FASP to make subscriptions — mastodon CWE-862 6.7 - 2026-02-24
CVE-2026-25540 Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`) — mastodon CWE-524 6.5 Medium 2026-02-04
CVE-2026-23964 Mastodon has insufficient access control to push notification settings — mastodon CWE-863 6.5 Medium 2026-01-22
CVE-2026-23963 Mastodon missing length limits on list names, filter names, and filter keywords — mastodon CWE-770 4.3 Medium 2026-01-22
CVE-2026-23962 Mastodon vulnerable to Denial of Service from a single post (client/server) — mastodon CWE-770 7.5 High 2026-01-22
CVE-2026-23961 Mastodon may allow a remote suspension bypass — mastodon CWE-863 5.3 Medium 2026-01-22
CVE-2026-22246 Local Mastodon users can enumerate and access severed relationships of every other local user — mastodon CWE-201 6.5 Medium 2026-01-08
CVE-2026-22245 Mastodon has SSRF Protection bypass — mastodon CWE-918 9.4 - 2026-01-08
CVE-2025-67500 Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration — mastodon CWE-204 3.7 Low 2025-12-09
CVE-2025-62605 Mastodon quotes control can be bypassed — mastodon CWE-754 4.3 Medium 2025-10-21
CVE-2025-62176 Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channels — mastodon CWE-280 4.3 Medium 2025-10-13
CVE-2025-62175 Mastodon streaming API fails to disconnect disabled and suspended users — mastodon CWE-273 4.3 Medium 2025-10-13
CVE-2025-62174 Mastodon allows continued access after password reset via CLI — mastodon CWE-613 3.5 Low 2025-10-13
CVE-2025-54879 Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails — mastodon CWE-770 5.3 Medium 2025-08-05
CVE-2025-27399 Mastodon's domain blocks & rationales ignore user approval when visibility set as "users" — mastodon CWE-200 5.3 Medium 2025-02-27

This page lists every published CVE security advisory associated with mastodon. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.