CVE-2026-46348: fallo de gravedad alta en mastodon
Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.4%
probabilidad de explotación
0.4%top 67% de las CVE
explotación observada
noninguna fuente lo reporta
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was lacking an IP address range that can be used to reach local IP addresses. An attacker can use an IP address in the affected range to make Mastodon perform HTTP requests against loopback interfaces, potentially allowing access to otherwise private resources and services. This vulnerability is fixed in 4.5.10, 4.4.17, and 4.3.23.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
mastodon · mastodonCVEs relacionadas — mastodon
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-36460CRITICALMastodon vulnerable to arbitrary file creation through media attachmentsEPSS 40.1%CVE-2024-23832CRITICALMastodon Remote user impersonation and takeoverEPSS 2.5%CVE-2023-36461HIGHMastodon vulnerable to Denial of Service through slow HTTP responsesEPSS 1.3%CVE-2023-28853HIGHMastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databaseEPSS 1.3%CVE-2023-36459CRITICALMastodon vulnerable to Cross-site Scripting through oEmbed preview cardsEPSS 1.2%CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS 0.8%