Mastodon, the widely deployed open-source social media platform, carries a concentrated vulnerability footprint that skews toward serious outcomes with a meaningful share reaching critical severity. The exposure centers on a single product and recurs through weakness classes characteristic of web applications handling user input and session state: resource exhaustion without throttling, authorization bypasses, cross-site scripting, and insufficient session expiration. These flaw patterns reflect the platform's role as an internet-facing service processing untrusted user-supplied content and managing authentication across distributed federated instances. Defenders running Mastodon instances should prioritize patching releases closely, as the platform's public deployment and federation model make it an attractive target; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joinmastodon over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36460CRITICAL Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully craft | Jul 6, 2023 | 9.9 | 55 | NO | NO |
CVE-2024-23832CRITICAL Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Ma | Feb 1, 2024 | 9.8 | 35 | NO | NO |
CVE-2022-24307CRITICAL Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since | Feb 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-33868MEDIUM Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) ex | Mar 27, 2026 | 6.1 | 31 | NO | YES |
CVE-2018-21018CRITICAL Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-27468HIGH Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5 | Feb 24, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-23962HIGH Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll | Jan 22, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-23963MEDIUM Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names | Jan 22, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-22245HIGH Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has | Jan 8, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-0432MEDIUM Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. | Feb 2, 2022 | 6.1 | 26 | NO | YES |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joinmastodon.
Media articles that mention a CVE ID that affects a product developed by Joinmastodon — matched by CVE ID, not by vendor name.