CVEs we hold for Mastodon
Records whose assigning authority named Mastodon as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-72916Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addressesmastodon CVE-2026-72915Mastodon: Personally-identifying information disclosure due to incorrect access control validationmastodon CVE-2026-72914Mastodon: Exhausting data by an unauthenticated request to the admin retention APImastodon CVE-2026-59825Mastodon: Unwanted deactivation of SSL/TLS certificate verificationmastodon CVE-2026-50129Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMERmastodon CVE-2026-48028Mastodon: Removal of integrity-protected JSON entries from signed activitiesmastodon CVE-2026-47777Mastodon has a consent-check bypass in its remote Collectionsmastodon CVE-2026-47389Mastodon: SSRF protection bypass on older Ruby versionsmastodon CVE-2026-46349Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuringmastodon CVE-2026-46348Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)mastodon CVE-2026-41259Mastodon: Insufficient verification of email addressesmastodon CVE-2026-33869Mastodon has a denial of service for quote authorizationmastodon CVE-2026-33868Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'mastodon CVE-2026-27477Mastodon has SSRF via unvalidated FASP Provider base_urlmastodon CVE-2026-27468Mastodon may allow unconfirmed FASP to make subscriptionsmastodon CVE-2026-25540Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache…mastodon CVE-2026-23964Mastodon has insufficient access control to push notification settingsmastodon CVE-2026-23963Mastodon missing length limits on list names, filter names, and filter keywordsmastodon CVE-2026-23962Mastodon vulnerable to Denial of Service from a single post (client/server)mastodon CVE-2026-22246Local Mastodon users can enumerate and access severed relationships of every other local usermastodon CVE-2025-67500Mastodon Error Handling Discrepancy Enables Private Status Existence Enumerationmastodon CVE-2025-62176Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channelsmastodon CVE-2025-62175Mastodon streaming API fails to disconnect disabled and suspended usersmastodon CVE-2025-62174Mastodon allows continued access after password reset via CLImastodon CVE-2025-54879Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsmastodon CVE-2025-27399Mastodon's domain blocks & rationales ignore user approval when visibility set as "users"mastodon CVE-2025-27157Mastodon's rate-limits are missing on `/auth/setup`mastodon CVE-2024-37903Mastodon has improper authorship check on audience extension for existing postsmastodon CVE-2024-25623Lack of media type verification of Activity Streams objects allows impersonation of remote accountsmastodon CVE-2024-25619Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodonmastodon CVE-2024-25618External OpenID Connect Account Takeover by E-Mail Change in mastodonmastodon CVE-2023-42452Mastodon vulnerable to Stored XSS through the translation featuremastodon CVE-2023-42451Mastodon Invalid Domain Name Normalization vulnerabilitymastodon CVE-2023-42450Mastodon Server-Side Request Forgery vulnerabilitymastodon CVE-2023-36462Mastodon's verified profile links can be formatted in a misleading waymastodon CVE-2023-36461Mastodon vulnerable to Denial of Service through slow HTTP responsesmastodon CVE-2023-36460Mastodon vulnerable to arbitrary file creation through media attachmentsmastodon CVE-2023-36459Mastodon vulnerable to Cross-site Scripting through oEmbed preview cardsmastodon CVE-2023-28853Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databasemastodon CVE-2022-2166Improper Restriction of Excessive Authentication Attempts in mastodon/mastodonmastodon/mastodon CVE-2022-0432Prototype Pollution in mastodon/mastodonmastodon/mastodon 46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.