Home/Product/joinmastodon mastodon
Product

joinmastodon mastodon

42 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-41259
< 4.3.22
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows
7.5HIGH
CVE-2026-33869
>= 4.4.0 and < 4.4.15
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on
4.8MEDIUM
CVE-2026-33868
< 4.3.21
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauth
4.3MEDIUM
CVE-2026-27477
>= 4.4.0 and < 4.4.14
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an admin
5.9MEDIUM
CVE-2026-27468
>= 4.4.0 and < 4.4.14
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an admin
8.2HIGH
CVE-2026-25540
< 4.3.19
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is v
6.5MEDIUM
CVE-2026-23964
< 4.3.18
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecu
6.5MEDIUM
CVE-2026-23963
< 4.3.18
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the serve
4.3MEDIUM
CVE-2026-23962
< 4.3.18
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5
7.5HIGH
CVE-2026-23961
< 4.3.18
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remot
5.3MEDIUM
CVE-2026-22246
< 4.3.17
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationsh
6.5MEDIUM
CVE-2026-22245
< 4.2.29
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound request
7.5HIGH
CVE-2025-67500
< 4.2.28
Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14
3.7LOW
CVE-2025-62605
>= 4.4.0 and < 4.4.8
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote
4.3MEDIUM
CVE-2025-62176
< 4.2.27
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the stre
4.3MEDIUM
CVE-2025-62175
< 4.2.27
Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disablin
4.3MEDIUM
CVE-2025-62174
< 4.2.27
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an
3.5LOW
CVE-2025-54879
>= 3.1.5 and < 4.2.24
Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authe
5.3MEDIUM
CVE-2025-27399
< 4.1.23
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility f
5.3MEDIUM
CVE-2025-27157
>= 4.2.0 and < 4.2.16
Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the
5.3MEDIUM
CVE-2023-49952
>= 4.1.0 and < 4.1.17
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
7.5HIGH
CVE-2024-34535
<= 4.1.16
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
5.9MEDIUM
CVE-2024-37903
>= 2.6.0 and < 4.1.18
Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by
8.2HIGH
CVE-2024-25623
< 3.5.19
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, w
8.5HIGH
CVE-2024-25619
< 3.5.18
Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming
3.1LOW
CVE-2024-25618
< 3.5.18
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authent
4.2MEDIUM
CVE-2024-23832
< 3.5.17
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authenticatio
9.4CRITICAL
CVE-2023-42452
>= 4.0.0 and < 4.0.10
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10
6.1MEDIUM
CVE-2023-42451
< 3.5.14
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2
7.4HIGH
CVE-2023-42450
all versions
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4
5.4MEDIUM
CVE-2023-36462
>= 2.6.0 and < 3.5.9
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9,
5.4MEDIUM
CVE-2023-36461
< 3.5.9
Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a
7.5HIGH
CVE-2023-36460
>= 3.5.0 and < 3.5.9
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9,
9.9CRITICAL
CVE-2023-36459
>= 1.3 and < 3.5.9
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4
9.3CRITICAL
CVE-2023-28853
>= 2.5.0 and < 3.5.8
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authenticatio
7.7HIGH
CVE-2022-48364
>= 3.5.0 and < 3.5.3
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use t
4.3MEDIUM
CVE-2022-46405
<= 4.0.2
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that foll
7.5HIGH
CVE-2022-2166
<= 3.5.5
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
9.8CRITICAL
CVE-2022-31263
< 3.5.0
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
5.3MEDIUM
CVE-2022-24307
< 3.3.2
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD acti
9.8CRITICAL
CVE-2022-0432
< 3.5.0
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
6.1MEDIUM
CVE-2018-21018
< 2.6.3
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin