Vulnerabilidades em mastodon

46 resultados
Análise Vexday

Mastodon apresenta 42 vulnerabilidades documentadas, com 4 classificadas como críticas, porém nenhuma sob ataque ativo conhecido. A fraqueza dominante (CWE-770 - alocação de recursos sem limite) sugere problemas de robustez na gestão de recursos. O ritmo recente de 8 CVEs nos últimos 90 dias indica atividade contínua de descoberta de vulnerabilidades, recomendando monitoramento regular de patches.

CVE-2026-25540MEDIUMMastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)EPSS 0.4%CVE-2026-46348HIGHMastodon: SSRF Bypass via IPv6 Unspecified Address (::)EPSS 0.4%CVE-2026-47389HIGHMastodon: SSRF protection bypass on older Ruby versionsEPSS 0.4%CVE-2024-25619LOWDestroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodonEPSS 0.4%CVE-2026-72916MEDIUMMastodon: SSRF Protection Bypass via IPv4-compatible IPv6 AddressesEPSS 0.4%CVE-2025-27157MEDIUMMastodon's rate-limits are missing on `/auth/setup`EPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2026-59825HIGHMastodon: Unwanted deactivation of SSL/TLS certificate verificationEPSS 0.3%CVE-2026-23963MEDIUMMastodon missing length limits on list names, filter names, and filter keywordsEPSS 0.3%CVE-2025-62605MEDIUMMastodon quotes control can be bypassedEPSS 0.3%CVE-2026-22245HIGHMastodon has SSRF Protection bypassEPSS 0.3%CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS 0.3%CVE-2026-27477MEDIUMMastodon has SSRF via unvalidated FASP Provider base_urlEPSS 0.3%CVE-2025-62176MEDIUMMastadon streaming server allows OAuth clients without the `read` scope to subscribe to public channelsEPSS 0.3%CVE-2026-22246MEDIUMLocal Mastodon users can enumerate and access severed relationships of every other local userEPSS 0.3%CVE-2026-27468MEDIUMMastodon may allow unconfirmed FASP to make subscriptionsEPSS 0.2%CVE-2025-62175MEDIUMMastodon streaming API fails to disconnect disabled and suspended usersEPSS 0.2%CVE-2026-23964MEDIUMMastodon has insufficient access control to push notification settingsEPSS 0.2%CVE-2025-67500LOWMastodon Error Handling Discrepancy Enables Private Status Existence EnumerationEPSS 0.2%CVE-2026-41259HIGHMastodon: Insufficient verification of email addressesEPSS 0.2%