CVE-2026-27468 is a high-severity vulnerability (CVSS 8.2) affecting Mastodon servers running experimental FASP features in versions 4.4.0-4.4.13 and 4.5.0-4.5.6. An unauthenticated attacker can bypass FASP approval to subscribe to lifecycle events and request content backfill, leading to minor information leakage and a significant Denial of Service (DoS) risk to the Sidekiq worker. While not actively exploited and lacking public exploit code, the vulnerability has garnered some community discussion. Organizations using the experimental FASP feature should update to versions 4.4.14 or 4.5.7 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, < 4.4.14CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.5.7CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.