VendorsJoinmastodonmastodonany version
Vulnerabilities

Joinmastodon Mastodon any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2023-36460
Mastodon vulnerable to arbitrary file creation through media attachments
Published 2023-07-06 · Modified
9.9EPSS 0.401
CVE-2018-21018
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
Published 2019-09-22 · Modified
9.8EPSS 0.026
CVE-2024-23832
Mastodon Remote user impersonation and takeover
Published 2024-02-01 · Modified
9.8EPSS 0.025
CVE-2022-24307
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
Published 2022-02-03 · Modified
9.8EPSS 0.014
CVE-2022-2166
Improper Restriction of Excessive Authentication Attempts in mastodon/mastodon
Published 2022-11-16 · Modified
9.8EPSS 0.011
CVE-2023-36459
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
Published 2023-07-06 · Modified
9.3EPSS 0.012
CVE-2024-25623
Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
Published 2024-02-19 · Analyzed
8.5EPSS 0.005
CVE-2024-37903
Mastodon has improper authorship check on audience extension for existing posts
Published 2024-07-05 · Analyzed
8.2EPSS 0.005
CVE-2026-27468
Mastodon may allow unconfirmed FASP to make subscriptions
Published 2026-02-24 · Analyzed
8.2EPSS 0.002
CVE-2026-41259
Mastodon: Insufficient verification of email addresses
Published 2026-04-23 · Analyzed
8.2EPSS 0.002
CVE-2023-28853
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
Published 2023-04-04 · Modified
7.7EPSS 0.013
CVE-2023-36461
Mastodon vulnerable to Denial of Service through slow HTTP responses
Published 2023-07-06 · Modified
7.5EPSS 0.013
CVE-2022-46405
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
Published 2022-12-04 · Modified
7.5EPSS 0.009
CVE-2023-42451
Mastodon Invalid Domain Name Normalization vulnerability
Published 2023-09-19 · Modified
7.5EPSS 0.007
CVE-2026-23962
Mastodon vulnerable to Denial of Service from a single post (client/server)
Published 2026-01-22 · Analyzed
7.5EPSS 0.005
CVE-2025-54879
Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
Published 2025-08-05 · Analyzed
7.5EPSS 0.005
CVE-2023-49952
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
Published 2024-11-18 · Analyzed
7.5EPSS 0.005
CVE-2026-22245
Mastodon has SSRF Protection bypass
Published 2026-01-08 · Analyzed
7.5EPSS 0.003
CVE-2022-0432
Prototype Pollution in mastodon/mastodon
Published 2022-02-02 · Modified
7.4EPSS 0.044
CVE-2024-25618
External OpenID Connect Account Takeover by E-Mail Change in mastodon
Published 2024-02-14 · Analyzed
7.4EPSS 0.005
CVE-2026-25540
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
Published 2026-02-04 · Analyzed
6.5EPSS 0.004
CVE-2026-23963
Mastodon missing length limits on list names, filter names, and filter keywords
Published 2026-01-22 · Analyzed
6.5EPSS 0.003
CVE-2026-22246
Local Mastodon users can enumerate and access severed relationships of every other local user
Published 2026-01-08 · Analyzed
6.5EPSS 0.003
CVE-2026-23964
Mastodon has insufficient access control to push notification settings
Published 2026-01-22 · Analyzed
6.5EPSS 0.002
CVE-2026-33868
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
Published 2026-03-27 · Analyzed
6.1EPSS 0.005
CVE-2023-42452
Mastodon vulnerable to Stored XSS through the translation feature
Published 2023-09-19 · Modified
6.1EPSS 0.004
CVE-2024-34535
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
Published 2024-10-03 · Analyzed
5.9EPSS 0.004
CVE-2026-27477
Mastodon has SSRF via unvalidated FASP Provider base_url
Published 2026-02-24 · Analyzed
5.9EPSS 0.003
CVE-2023-36462
Mastodon's verified profile links can be formatted in a misleading way
Published 2023-07-06 · Modified
5.4EPSS 0.006
CVE-2022-31263
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
Published 2022-05-24 · Modified
5.3EPSS 0.009
CVE-2026-23961
Mastodon may allow a remote suspension bypass
Published 2026-01-22 · Analyzed
5.3EPSS 0.004
CVE-2025-27157
Mastodon's rate-limits are missing on `/auth/setup`
Published 2025-02-27 · Analyzed
5.3EPSS 0.004
CVE-2025-27399
Mastodon's domain blocks & rationales ignore user approval when visibility set as "users"
Published 2025-02-27 · Analyzed
5.3EPSS 0.004
CVE-2026-33869
Mastodon has a denial of service for quote authorization
Published 2026-03-27 · Analyzed
4.8EPSS 0.002
CVE-2022-48364
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the appeal of a user whose status update was marked as sensitive.
Published 2023-03-06 · Modified
4.3EPSS 0.007
CVE-2024-25619
Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodon
Published 2024-02-14 · Analyzed
4.3EPSS 0.004
CVE-2025-62605
Mastodon quotes control can be bypassed
Published 2025-10-21 · Analyzed
4.3EPSS 0.003
CVE-2025-62176
Mastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channels
Published 2025-10-13 · Analyzed
4.3EPSS 0.003
CVE-2025-62175
Mastodon streaming API fails to disconnect disabled and suspended users
Published 2025-10-13 · Analyzed
4.3EPSS 0.002
CVE-2025-67500
Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration
Published 2025-12-09 · Analyzed
3.7EPSS 0.002
1 / 2Next →