Joinmastodon

Mastodon

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 08.01.2026 15:23:13
  • Zuletzt bearbeitet 15.01.2026 20:36:42

Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses ...

  • EPSS 0.07%
  • Veröffentlicht 09.12.2025 23:44:04
  • Zuletzt bearbeitet 19.12.2025 19:29:53

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow checking wheth...

  • EPSS 0.05%
  • Veröffentlicht 21.10.2025 16:46:37
  • Zuletzt bearbeitet 12.12.2025 13:39:29

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions pr...

  • EPSS 0.06%
  • Veröffentlicht 13.10.2025 21:15:35
  • Zuletzt bearbeitet 20.10.2025 17:19:19

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those ...

  • EPSS 0.05%
  • Veröffentlicht 13.10.2025 20:59:31
  • Zuletzt bearbeitet 20.10.2025 17:19:58

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended...

  • EPSS 0.04%
  • Veröffentlicht 13.10.2025 20:54:36
  • Zuletzt bearbeitet 20.10.2025 17:20:08

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --rese...

  • EPSS 0.11%
  • Veröffentlicht 05.08.2025 23:39:59
  • Zuletzt bearbeitet 26.08.2025 13:57:17

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting syst...

  • EPSS 0.45%
  • Veröffentlicht 27.02.2025 18:15:30
  • Zuletzt bearbeitet 24.06.2025 15:59:22

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet appr...

  • EPSS 0.24%
  • Veröffentlicht 27.02.2025 17:15:16
  • Zuletzt bearbeitet 24.06.2025 15:59:59

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an e...

  • EPSS 0.2%
  • Veröffentlicht 18.11.2024 18:15:05
  • Zuletzt bearbeitet 07.05.2025 13:38:59

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.