Vulnerabilities in mastodon
46 resultsVexday analysis
Mastodon apresenta 42 vulnerabilidades documentadas, com 4 classificadas como críticas, porém nenhuma sob ataque ativo conhecido. A fraqueza dominante (CWE-770 - alocação de recursos sem limite) sugere problemas de robustez na gestão de recursos. O ritmo recente de 8 CVEs nos últimos 90 dias indica atividade contínua de descoberta de vulnerabilidades, recomendando monitoramento regular de patches.
CVE-2023-36460CRITICALMastodon vulnerable to arbitrary file creation through media attachmentsEPSS 40.1%CVE-2022-0432HIGHPrototype Pollution in mastodon/mastodonEPSS 4.4%CVE-2024-23832CRITICALMastodon Remote user impersonation and takeoverEPSS 2.5%CVE-2023-36461HIGHMastodon vulnerable to Denial of Service through slow HTTP responsesEPSS 1.3%CVE-2023-28853HIGHMastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databaseEPSS 1.3%CVE-2023-36459CRITICALMastodon vulnerable to Cross-site Scripting through oEmbed preview cardsEPSS 1.2%CVE-2022-2166CRITICALImproper Restriction of Excessive Authentication Attempts in mastodon/mastodonEPSS 1.1%CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS 0.8%CVE-2023-42451HIGHMastodon Invalid Domain Name Normalization vulnerabilityEPSS 0.7%CVE-2023-36462MEDIUMMastodon's verified profile links can be formatted in a misleading wayEPSS 0.6%CVE-2026-72916MEDIUMMastodon: SSRF Protection Bypass via IPv4-compatible IPv6 AddressesEPSS 0.6%CVE-2026-33868MEDIUMMastodon has a GET-Based Open Redirect via '/web/%2F<domain>'EPSS 0.6%CVE-2026-23962HIGHMastodon vulnerable to Denial of Service from a single post (client/server)EPSS 0.5%CVE-2025-54879MEDIUMMastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsEPSS 0.5%CVE-2024-37903HIGHMastodon has improper authorship check on audience extension for existing postsEPSS 0.5%CVE-2024-25623HIGHLack of media type verification of Activity Streams objects allows impersonation of remote accountsEPSS 0.5%CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS 0.5%CVE-2024-25618MEDIUMExternal OpenID Connect Account Takeover by E-Mail Change in mastodonEPSS 0.5%CVE-2023-42450MEDIUMMastodon Server-Side Request Forgery vulnerabilityEPSS 0.5%CVE-2026-50129HIGHMastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMEREPSS 0.5%