vciy

CVEs we hold for Mastodon

Records whose assigning authority named Mastodon as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-72916Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addressesmastodon
CVE-2026-72915Mastodon: Personally-identifying information disclosure due to incorrect access control validationmastodon
CVE-2026-72914Mastodon: Exhausting data by an unauthenticated request to the admin retention APImastodon
CVE-2026-59825Mastodon: Unwanted deactivation of SSL/TLS certificate verificationmastodon
CVE-2026-50129Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMERmastodon
CVE-2026-50128Mastodon: Spoofing of attribution domainsmastodon
CVE-2026-48028Mastodon: Removal of integrity-protected JSON entries from signed activitiesmastodon
CVE-2026-47777Mastodon has a consent-check bypass in its remote Collectionsmastodon
CVE-2026-47389Mastodon: SSRF protection bypass on older Ruby versionsmastodon
CVE-2026-46349Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuringmastodon
CVE-2026-46348Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)mastodon
CVE-2026-41259Mastodon: Insufficient verification of email addressesmastodon
CVE-2026-33869Mastodon has a denial of service for quote authorizationmastodon
CVE-2026-33868Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'mastodon
CVE-2026-27477Mastodon has SSRF via unvalidated FASP Provider base_urlmastodon
CVE-2026-27468Mastodon may allow unconfirmed FASP to make subscriptionsmastodon
CVE-2026-25540Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache…mastodon
CVE-2026-23964Mastodon has insufficient access control to push notification settingsmastodon
CVE-2026-23963Mastodon missing length limits on list names, filter names, and filter keywordsmastodon
CVE-2026-23962Mastodon vulnerable to Denial of Service from a single post (client/server)mastodon
CVE-2026-23961Mastodon may allow a remote suspension bypassmastodon
CVE-2026-22246Local Mastodon users can enumerate and access severed relationships of every other local usermastodon
CVE-2026-22245Mastodon has SSRF Protection bypassmastodon
CVE-2025-67500Mastodon Error Handling Discrepancy Enables Private Status Existence Enumerationmastodon
CVE-2025-62605Mastodon quotes control can be bypassedmastodon
CVE-2025-62176Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channelsmastodon
CVE-2025-62175Mastodon streaming API fails to disconnect disabled and suspended usersmastodon
CVE-2025-62174Mastodon allows continued access after password reset via CLImastodon
CVE-2025-54879Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsmastodon
CVE-2025-27399Mastodon's domain blocks & rationales ignore user approval when visibility set as "users"mastodon
CVE-2025-27157Mastodon's rate-limits are missing on `/auth/setup`mastodon
CVE-2024-37903Mastodon has improper authorship check on audience extension for existing postsmastodon
CVE-2024-25623Lack of media type verification of Activity Streams objects allows impersonation of remote accountsmastodon
CVE-2024-25619Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodonmastodon
CVE-2024-25618External OpenID Connect Account Takeover by E-Mail Change in mastodonmastodon
CVE-2024-23832Mastodon Remote user impersonation and takeovermastodon
CVE-2023-42452Mastodon vulnerable to Stored XSS through the translation featuremastodon
CVE-2023-42451Mastodon Invalid Domain Name Normalization vulnerabilitymastodon
CVE-2023-42450Mastodon Server-Side Request Forgery vulnerabilitymastodon
CVE-2023-36462Mastodon's verified profile links can be formatted in a misleading waymastodon
CVE-2023-36461Mastodon vulnerable to Denial of Service through slow HTTP responsesmastodon
CVE-2023-36460Mastodon vulnerable to arbitrary file creation through media attachmentsmastodon
CVE-2023-36459Mastodon vulnerable to Cross-site Scripting through oEmbed preview cardsmastodon
CVE-2023-28853Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databasemastodon
CVE-2022-2166Improper Restriction of Excessive Authentication Attempts in mastodon/mastodonmastodon/mastodon
CVE-2022-0432Prototype Pollution in mastodon/mastodonmastodon/mastodon

46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.