CVE-2026-33869
- EPSS 0.05%
- Veröffentlicht 27.03.2026 19:52:21
- Zuletzt bearbeitet 30.03.2026 19:12:07
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from b...
CVE-2026-33868
- EPSS 0.94%
- Veröffentlicht 27.03.2026 19:50:07
- Zuletzt bearbeitet 30.03.2026 19:14:17
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded pat...
CVE-2026-27477
- EPSS 0.07%
- Veröffentlicht 24.02.2026 19:00:20
- Zuletzt bearbeitet 26.02.2026 21:17:15
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with...
CVE-2026-27468
- EPSS 0.06%
- Veröffentlicht 24.02.2026 17:12:40
- Zuletzt bearbeitet 26.02.2026 15:36:00
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/...
CVE-2026-25540
- EPSS 0.02%
- Veröffentlicht 04.02.2026 21:42:09
- Zuletzt bearbeitet 20.02.2026 21:02:56
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinne...
CVE-2026-23964
- EPSS 0.04%
- Veröffentlicht 22.01.2026 01:55:29
- Zuletzt bearbeitet 02.02.2026 20:26:10
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user'...
CVE-2026-23963
- EPSS 0.07%
- Veröffentlicht 22.01.2026 01:53:49
- Zuletzt bearbeitet 02.02.2026 20:27:15
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set ...
CVE-2026-23962
- EPSS 0.02%
- Veröffentlicht 22.01.2026 01:51:37
- Zuletzt bearbeitet 02.02.2026 20:27:51
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a ve...
CVE-2026-23961
- EPSS 0.02%
- Veröffentlicht 22.01.2026 01:47:36
- Zuletzt bearbeitet 02.02.2026 20:29:07
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appea...
CVE-2026-22246
- EPSS 0.05%
- Veröffentlicht 08.01.2026 15:27:21
- Zuletzt bearbeitet 22.01.2026 13:52:28
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing u...