📦 Mastodon

by Joinmastodon

🔍 What is Mastodon?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-23832

CRITICAL CVSS 9.4 Feb 1, 2024

This vulnerability in Mastodon's LDAP authentication allows attackers to impersonate and take over any remote account due to insufficient origin validation. All Mastodon instances using LDAP authentic...

CVE-2023-36459

CRITICAL CVSS 9.3 Jul 6, 2023

This vulnerability allows attackers to inject arbitrary HTML into Mastodon oEmbed preview cards by bypassing HTML sanitization. When users click on malicious links with crafted oEmbed data, cross-site...

CVE-2022-24307

CRITICAL CVSS 9.8 Feb 3, 2022

Mastodon instances running vulnerable versions have incorrect access control due to improper handling of signed JSON-LD activities. This allows attackers to bypass intended access restrictions and pot...

CVE-2026-23962

HIGH CVSS 7.5 Jan 22, 2026

Mastodon servers running vulnerable versions allow attackers to create remote posts with unlimited poll options, causing excessive resource consumption. This can lead to denial of service on both serv...

CVE-2026-22245

HIGH CVSS 7.5 Jan 8, 2026

Mastodon's IP address filtering mechanism had incomplete coverage, allowing attackers to bypass protections against local network requests. This enables Server-Side Request Forgery (SSRF) attacks wher...

CVE-2024-37903

HIGH CVSS 8.2 Jul 5, 2024

This CVE describes an authorization bypass vulnerability in Mastodon where attackers can craft specific activities to extend the audience of posts they don't own, gaining unauthorized access to privat...

CVE-2023-42451

HIGH CVSS 7.4 Sep 19, 2023

This vulnerability in Mastodon allows attackers to spoof domains they don't own by exploiting flaws in domain name normalization. This could enable impersonation attacks, phishing, or unauthorized acc...

CVE-2023-36461

HIGH CVSS 7.5 Jul 6, 2023

This vulnerability in Mastodon allows malicious servers to perform slowloris-type attacks by extending HTTP response durations indefinitely. This can exhaust all Mastodon workers, making the server un...

CVE-2023-28853

HIGH CVSS 7.7 Apr 4, 2023

This vulnerability allows attackers to perform LDAP injection attacks on Mastodon instances configured with LDAP authentication. By manipulating login queries, attackers can extract arbitrary attribut...

CVE-2026-27477

MEDIUM CVSS 5.9 Feb 24, 2026

This vulnerability allows unauthenticated attackers to register FASP accounts with attacker-controlled base URLs that point to internal systems, forcing Mastodon servers to make HTTP(S) requests to in...

CVE-2026-25540

MEDIUM CVSS 6.5 Feb 4, 2026

Mastodon servers with AUTHORIZED_FETCH enabled are vulnerable to web cache poisoning where ActivityPub endpoints for pinned posts and featured hashtags incorrectly reuse cached responses regardless of...

CVE-2026-23963

MEDIUM CVSS 4.3 Jan 22, 2026

Mastodon servers prior to patched versions allow users to set arbitrarily long names for lists/filters and filter keywords, enabling resource exhaustion attacks. Any authenticated user can exploit thi...

CVE-2026-23964

MEDIUM CVSS 6.5 Jan 22, 2026

This CVE describes an insecure direct object reference vulnerability in Mastodon's web push subscription update endpoint. Authenticated users can tamper with other users' push notification settings by...

CVE-2026-23961

MEDIUM CVSS 5.3 Jan 22, 2026

This CVE describes a logic error in Mastodon's user suspension feature that allows posts from suspended remote users to appear in timelines. All Mastodon versions are affected by occasional display of...

CVE-2026-22246

MEDIUM CVSS 6.5 Jan 8, 2026

This vulnerability in Mastodon allows any registered local user to access lists of severed relationships (lost followers/followed users) from moderation events without authorization. The leaked inform...

CVE-2025-62605

MEDIUM CVSS 4.3 Oct 21, 2025

This vulnerability allows attackers to bypass quote controls in Mastodon by reblogging a post and then quoting their own reblog, effectively quoting content they weren't authorized to quote. This affe...

CVE-2025-62176

MEDIUM CVSS 4.3 Oct 13, 2025

Mastodon's streaming server incorrectly allows OAuth clients with valid authentication tokens to subscribe to public timeline events even when those tokens lack the required read:statuses scope. This ...

CVE-2025-62175

MEDIUM CVSS 4.3 Oct 13, 2025

Mastodon servers running vulnerable versions allow disabled or suspended user accounts to maintain real-time streaming API connections, receiving updates despite being blocked from other interactions....

CVE-2025-54879

MEDIUM CVSS 5.3 Aug 6, 2025

This vulnerability allows attackers to bypass email confirmation rate limits in Mastodon by rotating IP addresses, enabling them to send unlimited confirmation emails to any email address. This can le...

CVE-2025-27399

MEDIUM CVSS 5.3 Feb 27, 2025

Mastodon instances with domain block visibility set to 'users' (logged-in users) inadvertently expose block reasons to unapproved users. This affects instance administrators who want to keep domain bl...

CVE-2025-67500

LOW CVSS 3.7 Dec 10, 2025

This vulnerability in Mastodon allows attackers to confirm the existence of private statuses by sending requests with non-English Accept-Language headers. While it doesn't reveal content or other prop...