Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mastodon — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in mastodon, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) associated with the Mastodon social networking platform. It aggregates historical security vulnerabilities affecting the core codebase, third-party dependencies, and associated infrastructure components. The collection covers reports from the platform’s initial public releases through the current version, providing a comprehensive timeline of discovered flaws. Here, you can track how the vendor has addressed specific advisories over time, understand the prevalence and nature of specific weakness classes within the Mastodon ecosystem, and look up the full vulnerability history of the product to assess its security posture. The data includes details on severity ratings, attack vectors, and the status of fixes or patches. This resource is intended for security researchers, system administrators, and developers who need to evaluate the risk landscape of deploying or maintaining a Mastodon instance. By analyzing trends in reported issues, users can better anticipate potential attack surfaces and implement appropriate mitigation strategies. The information is sourced from official vendor announcements, public vulnerability databases, and community security reports, ensuring a reliable record of the product’s security evolution. This aggregation serves as a reference point for understanding the historical context of security incidents in open-source social media software.

Vendor: mastodon

CVE IDTitleCVSSSeverityPublished
CVE-2026-72916 Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses CWE-918 6.3 Medium2026-08-10
CVE-2026-72915 Mastodon: Personally-identifying information disclosure due to incorrect access control validation CWE-200 7.5 High2026-08-10
CVE-2026-72914 Mastodon: Exhausting data by an unauthenticated request to the admin retention API CWE-405 7.5 High2026-08-10
CVE-2026-50129 Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER CWE-248 7.5 High2026-06-24
CVE-2026-50128 Mastodon: Spoofing of attribution domains CWE-354 5.3 Medium2026-06-24
CVE-2026-48028 Mastodon: Removal of integrity-protected JSON entries from signed activities CWE-354 6.5 Medium2026-06-24
CVE-2026-47389 Mastodon: SSRF protection bypass on older Ruby versions CWE-184 8.6 High2026-06-24
CVE-2026-46349 Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring CWE-347 5.3 Medium2026-06-24
CVE-2026-46348 Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) CWE-918--2026-06-24
CVE-2026-47777 Mastodon has a consent-check bypass in its remote Collections CWE-345 7.5 High2026-06-15
CVE-2026-41259 Mastodon: Insufficient verification of email addresses CWE-841 4.3AIMediumAI2026-04-23
CVE-2026-33869 Mastodon has a denial of service for quote authorization CWE-863 4.8 Medium2026-03-27
CVE-2026-33868 Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>' CWE-601 4.3 Medium2026-03-27
CVE-2026-27477 Mastodon has SSRF via unvalidated FASP Provider base_url CWE-918 6.5 -2026-02-24
CVE-2026-27468 Mastodon may allow unconfirmed FASP to make subscriptions CWE-862 6.7 -2026-02-24
CVE-2026-25540 Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`) CWE-524 6.5 Medium2026-02-04
CVE-2026-23964 Mastodon has insufficient access control to push notification settings CWE-863 6.5 Medium2026-01-22
CVE-2026-23963 Mastodon missing length limits on list names, filter names, and filter keywords CWE-770 4.3 Medium2026-01-22
CVE-2026-23962 Mastodon vulnerable to Denial of Service from a single post (client/server) CWE-770 7.5 High2026-01-22
CVE-2026-23961 Mastodon may allow a remote suspension bypass CWE-863 5.3 Medium2026-01-22
CVE-2026-22246 Local Mastodon users can enumerate and access severed relationships of every other local user CWE-201 6.5 Medium2026-01-08
CVE-2026-22245 Mastodon has SSRF Protection bypass CWE-918 9.4 -2026-01-08
CVE-2025-67500 Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration CWE-204 3.7 Low2025-12-09
CVE-2025-62605 Mastodon quotes control can be bypassed CWE-754 4.3 Medium2025-10-21
CVE-2025-62176 Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channels CWE-280 4.3 Medium2025-10-13
CVE-2025-62175 Mastodon streaming API fails to disconnect disabled and suspended users CWE-273 4.3 Medium2025-10-13
CVE-2025-62174 Mastodon allows continued access after password reset via CLI CWE-613 3.5 Low2025-10-13
CVE-2025-54879 Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails CWE-770 5.3 Medium2025-08-05
CVE-2025-27399 Mastodon's domain blocks & rationales ignore user approval when visibility set as "users" CWE-200 5.3 Medium2025-02-27
CVE-2025-27157 Mastodon's rate-limits are missing on `/auth/setup` CWE-770 5.3 Medium2025-02-27

All 43 known CVE vulnerabilities affecting mastodon with full Chinese analysis, references, and POCs where available.