Joinmastodon

Mastodon

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 21.10.2025 16:46:37
  • Zuletzt bearbeitet 12.12.2025 13:39:29

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions pr...

  • EPSS 0.09%
  • Veröffentlicht 13.10.2025 21:15:35
  • Zuletzt bearbeitet 20.10.2025 17:19:19

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those ...

  • EPSS 0.06%
  • Veröffentlicht 13.10.2025 20:59:31
  • Zuletzt bearbeitet 20.10.2025 17:19:58

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended...

  • EPSS 0.06%
  • Veröffentlicht 13.10.2025 20:54:36
  • Zuletzt bearbeitet 20.10.2025 17:20:08

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --rese...

  • EPSS 0.13%
  • Veröffentlicht 05.08.2025 23:39:59
  • Zuletzt bearbeitet 26.08.2025 13:57:17

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting syst...

  • EPSS 0.24%
  • Veröffentlicht 27.02.2025 18:15:30
  • Zuletzt bearbeitet 24.06.2025 15:59:22

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet appr...

  • EPSS 0.23%
  • Veröffentlicht 27.02.2025 17:15:16
  • Zuletzt bearbeitet 24.06.2025 15:59:59

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an e...

  • EPSS 0.2%
  • Veröffentlicht 18.11.2024 18:15:05
  • Zuletzt bearbeitet 07.05.2025 13:38:59

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

  • EPSS 0.07%
  • Veröffentlicht 03.10.2024 18:15:04
  • Zuletzt bearbeitet 06.05.2025 18:30:39

In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

  • EPSS 0.85%
  • Veröffentlicht 05.07.2024 18:15:32
  • Zuletzt bearbeitet 24.06.2025 16:04:05

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on ...