mastodon
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mastodon.
- CVE-2026-59825Mastodon: Unwanted deactivation of SSL/TLS certificate verification7.4
- CVE-2026-72915Mastodon: Personally-identifying information disclosure due to incorrect access control validation7.5
- CVE-2026-72914Mastodon: Exhausting data by an unauthenticated request to the admin retention API7.5
- CVE-2026-50129Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER7.5
- CVE-2026-50128Mastodon: Spoofing of attribution domains5.3
- CVE-2026-48028Mastodon: Removal of integrity-protected JSON entries from signed activities6.5
- CVE-2026-47389Mastodon: SSRF protection bypass on older Ruby versions8.6
- CVE-2026-46349Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring5.3
- CVE-2026-47777Mastodon has a consent-check bypass in its remote Collections7.5
- CVE-2026-41259Mastodon: Insufficient verification of email addresses7.5
- CVE-2026-33869Mastodon has a denial of service for quote authorization4.8
- CVE-2026-33868Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'4.3
- CVE-2026-27477Mastodon has SSRF via unvalidated FASP Provider base_url5.9
- CVE-2026-27468Mastodon may allow unconfirmed FASP to make subscriptions8.2
- CVE-2026-25540Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)6.5