Joinmastodon

Mastodon

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 24.02.2026 19:00:20
  • Zuletzt bearbeitet 26.02.2026 21:17:15

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with...

  • EPSS 0.05%
  • Veröffentlicht 24.02.2026 17:12:40
  • Zuletzt bearbeitet 26.02.2026 15:36:00

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/...

  • EPSS 0.05%
  • Veröffentlicht 04.02.2026 21:42:09
  • Zuletzt bearbeitet 20.02.2026 21:02:56

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinne...

  • EPSS 0.04%
  • Veröffentlicht 22.01.2026 01:55:29
  • Zuletzt bearbeitet 02.02.2026 20:26:10

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user'...

  • EPSS 0.06%
  • Veröffentlicht 22.01.2026 01:53:49
  • Zuletzt bearbeitet 02.02.2026 20:27:15

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set ...

  • EPSS 0.02%
  • Veröffentlicht 22.01.2026 01:51:37
  • Zuletzt bearbeitet 02.02.2026 20:27:51

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a ve...

  • EPSS 0.06%
  • Veröffentlicht 22.01.2026 01:47:36
  • Zuletzt bearbeitet 02.02.2026 20:29:07

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appea...

  • EPSS 0.04%
  • Veröffentlicht 08.01.2026 15:27:21
  • Zuletzt bearbeitet 22.01.2026 13:52:28

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing u...

  • EPSS 0.04%
  • Veröffentlicht 08.01.2026 15:23:13
  • Zuletzt bearbeitet 15.01.2026 20:36:42

Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses ...

  • EPSS 0.06%
  • Veröffentlicht 09.12.2025 23:44:04
  • Zuletzt bearbeitet 19.12.2025 19:29:53

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking wheth...