<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Mastodon</title>
  <link>https://cvedaily.com/pages/tags/mastodon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mastodon.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Mastodon</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41259 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41259</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41259</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-841</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33869 – Mastodon is a free, open-source social network server based on ActivityPub. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33869</guid>
    <pubDate>Fri, 27 Mar 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33869</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected b…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33868 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33868</guid>
    <pubDate>Fri, 27 Mar 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33868</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially encoded URL that causes the application to redirect users to an arbitrary external domain, enabling phi…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27477 – Mastodon is a free, open-source social network server based on ActivityPub. FASP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27477</guid>
    <pubDate>Tue, 24 Feb 2026 20:27:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27477</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with an attacker-chosen `base_url` that includes or resolves to a local / internal address, leading to the Mastodon server making requests to that addres…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27468 – Mastodon is a free, open-source social network server based on ActivityPub. FASP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27468</guid>
    <pubDate>Tue, 24 Feb 2026 18:29:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27468</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to backfill content did not check properly whether the FASP was actually approved. This only affects Mastodon servers tha…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25540 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25540</guid>
    <pubDate>Wed, 04 Feb 2026 22:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25540</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinned posts and featured hashtags have contents that depend on the account that signed the HTTP request. However, these contents are stored in an interna…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23964 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23964</guid>
    <pubDate>Thu, 22 Jan 2026 03:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23964</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the numeric subscription id. This can be used to disrupt push notifications for other users and also lea…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23963 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23963</guid>
    <pubDate>Thu, 22 Jan 2026 03:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23963</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as the name or keyword. Any local user can abuse the list or filter fields to cause disproportionate storage and computing…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23962 – Mastodon is a free, open-source social network server based on ActivityPub. Mast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23962</guid>
    <pubDate>Thu, 22 Jan 2026 03:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23962</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, greatly increasing resource consumption. Depending on the number of poll options, an attacker can cause disproportionate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23961 – Mastodon is a free, open-source social network server based on ActivityPub. Mast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23961</guid>
    <pubDate>Thu, 22 Jan 2026 02:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23961</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under certain circumstances, previously-unknown posts from suspended users can be processed. This issue allow…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22246 – Mastodon is a free, open-source social network server based on ActivityPub. Mast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22246</guid>
    <pubDate>Thu, 08 Jan 2026 16:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22246</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of severed relationships for a particular event fails to check the owner of the list before returning the lost relationships.…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22245 – Mastodon is a free, open-source social network server based on ActivityPub. By n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22245</guid>
    <pubDate>Thu, 08 Jan 2026 16:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22245</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_PRIVATE_ADDRESSES`) to avoid the "confused deputy" problem. The list of disallowed IP address ranges was lacking some I…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-67500 – Mastodon is a free, open-source social network server based on ActivityPub. Vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67500</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-67500</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking whether a given status exists by sending a request with a non-English Accept-Language header. Using this behavior, an attacker who knows the identifier of…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62605 – Mastodon is a free, open-source social network server based on ActivityPub. In M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62605</guid>
    <pubDate>Tue, 21 Oct 2025 17:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62605</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2. Mastodon internally treats reblogs as statuses. Since they were not special-treated, an attacker could reblog any post…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62176 – Mastodon is a free, open-source social network server based on ActivityPub. In M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62176</guid>
    <pubDate>Mon, 13 Oct 2025 21:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62176</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses scope. This allows OAuth clients without the read scope to subscribe to public channels and receive public timeline eve…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62175 – Mastodon is a free, open-source social network server based on ActivityPub. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62175</guid>
    <pubDate>Mon, 13 Oct 2025 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62175</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing streaming connections and to establish new streaming connections, even though they…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62174 – Mastodon is a free, open-source social network server based on ActivityPub.  In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62174</guid>
    <pubDate>Mon, 13 Oct 2025 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62174</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub.  In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions and access tokens for that account are not revoked. This allows an attacker with access to a previously compromised sess…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54879 – Mastodon is a free, open-source social network server based on ActivityPub Masto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54879</guid>
    <pubDate>Wed, 06 Aug 2025 00:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54879</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical configuration error where the email-based throttle for confirmation emails incorrectly checks the password reset path instead of th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5528 – The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5528</guid>
    <pubDate>Sat, 07 Jun 2025 12:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5528</strong></p>
  <p>The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22660 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22660</guid>
    <pubDate>Thu, 27 Mar 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22660</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: from n/a through <= 1.9.9.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27399 – Mastodon is a self-hosted, federated microblogging platform. In versions prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27399</guid>
    <pubDate>Thu, 27 Feb 2025 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27399</strong></p>
  <p>Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 f…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27157 – Mastodon is a self-hosted, federated microblogging platform. Starting in version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27157</guid>
    <pubDate>Thu, 27 Feb 2025 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27157</strong></p>
  <p>Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11252 – The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11252</guid>
    <pubDate>Sat, 30 Nov 2024 06:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11252</strong></p>
  <p>The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11455 – The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11455</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11455</strong></p>
  <p>The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49952 – Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49952</guid>
    <pubDate>Mon, 18 Nov 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49952</strong></p>
  <p>Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34535 – In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a craft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34535</guid>
    <pubDate>Thu, 03 Oct 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34535</strong></p>
  <p>In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37903 – Mastodon is a self-hosted, federated microblogging platform. Starting in version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37903</guid>
    <pubDate>Fri, 05 Jul 2024 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37903</strong></p>
  <p>Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining access to the contents of a post not intended for them. Versions 4.1.18 and 4.2.10 contain a patch for this issue.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25623 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25623</guid>
    <pubDate>Mon, 19 Feb 2024 16:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25623</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a M…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-25619 – Mastodon is a free, open-source social network server based on ActivityPub. When...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25619</guid>
    <pubDate>Wed, 14 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-25619</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application to continue listening to streaming after the application had been destroyed. Essentially this comes down to the fact th…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25618 – Mastodon is a free, open-source social network server based on ActivityPub. Mast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25618</guid>
    <pubDate>Wed, 14 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25618</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a possible account takeover if the authentication provider allows changing the e-mail address or multiple authentication providers are configured. When a…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23832 – Mastodon is a free, open-source social network server based on ActivityPub Masto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23832</guid>
    <pubDate>Thu, 01 Feb 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23832</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prio…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42452 – Mastodon is a free, open-source social network server based on ActivityPub. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42452</guid>
    <pubDate>Tue, 19 Sep 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42452</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing unescaped HTML to execute in the browser. The impact is limited thanks to Mastodon's strict Content Security Policy, bloc…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42451 – Mastodon is a free, open-source social network server based on ActivityPub. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42451</guid>
    <pubDate>Tue, 19 Sep 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42451</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42450 – Mastodon is a free, open-source social network server based on ActivityPub. Star...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42450</guid>
    <pubDate>Tue, 19 Sep 2023 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42450</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This can be used to perform confused deputy attacks if the server configuration includes `ALLOWED_PRIVATE_ADDRESSES` to allow access to local exploitable se…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-113</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36462 – Mastodon is a free, open-source social network server based on ActivityPub. Star...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36462</guid>
    <pubDate>Thu, 06 Jul 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36462</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to appear to link to a different URL altogether. The link is visually misleading, but clicking on it will reveal the actual li…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36461 – Mastodon is a free, open-source social network server based on ActivityPub. When...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36461</guid>
    <pubDate>Thu, 06 Jul 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36461</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks. This vulnerability can be used to keep all Mastodon workers busy for an extended d…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36460 – Mastodon is a free, open-source social network server based on ActivityPub. Star...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36460</guid>
    <pubDate>Thu, 06 Jul 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36460</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrar…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36459 – Mastodon is a free, open-source social network server based on ActivityPub. Star...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36459</guid>
    <pubDate>Thu, 06 Jul 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36459</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a vector for cross-site scripting (XSS) payloads that can be rendered in the user…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28853 – Mastodon is a free, open-source social network server based on ActivityPub Masto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28853</guid>
    <pubDate>Tue, 04 Apr 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28853</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, an…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-48364 – The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48364</guid>
    <pubDate>Mon, 06 Mar 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-48364</strong></p>
  <p>The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the appeal of a user whose status update was marked as sensitive.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46405 – Mastodon through 4.0.2 allows attackers to cause a denial of service (large Side...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46405</guid>
    <pubDate>Sun, 04 Dec 2022 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46405</strong></p>
  <p>Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-2166 – Improper Restriction of Excessive Authentication Attempts in GitHub repository m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2166</guid>
    <pubDate>Wed, 16 Nov 2022 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-2166</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31263 – app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31263</guid>
    <pubDate>Tue, 24 May 2022 04:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31263</strong></p>
  <p>app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24307 – Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control becaus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24307</guid>
    <pubDate>Thu, 03 Feb 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24307</strong></p>
  <p>Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0432 – Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0432</guid>
    <pubDate>Wed, 02 Feb 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0432</strong></p>
  <p>Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21269 – Keymaker is a Mastodon Community Finder based Matrix Community serverlist page S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21269</guid>
    <pubDate>Wed, 20 Jan 2021 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21269</strong></p>
  <p>Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a Path Traversal attack causing to read more files than allowed. This is fixed in version 0.2.0.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-21018 – Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21018</guid>
    <pubDate>Sun, 22 Sep 2019 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-21018</strong></p>
  <p>Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5961 – The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5961</guid>
    <pubDate>Fri, 05 Jul 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5961</strong></p>
  <p>The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5961">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
