Mastodon
Vendor:
First CVE: Sep 22, 2019 · Active for 6 years
42
Total CVEs
More Total CVEs than 97% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mastodon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2019
6 years ago
Most Recent CVE
Apr 23, 2026
94 days ago
CVE Severity & Scoring
Mastodon42 CVEs
52%
31%
12%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (88.1%)
High5 (11.9%)
Unknown0 (0.0%)
User Interaction
None36 (85.7%)
Unknown0 (0.0%)
Required6 (14.3%)
Privileges Required
Low14 (33.3%)
High0 (0.0%)
None28 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36460CRITICAL Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully craft | Jul 6, 2023 | 9.9 | 55 | NO | NO |
CVE-2024-23832CRITICAL Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Ma | Feb 1, 2024 | 9.8 | 35 | NO | NO |
CVE-2022-24307CRITICAL Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since | Feb 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-33868MEDIUM Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) ex | Mar 27, 2026 | 6.1 | 31 | NO | YES |
CVE-2018-21018CRITICAL Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-27468HIGH Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5 | Feb 24, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-23962HIGH Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll | Jan 22, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-23963MEDIUM Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names | Jan 22, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-22245HIGH Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has | Jan 8, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-0432MEDIUM Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. | Feb 2, 2022 | 6.1 | 26 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (42 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (42 CVEs).
Media Mentions
Signals from CVEs in this product scope (42 CVEs).
Top CNAs Publishing CVEs For Mastodon
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5.0 | 1 | 4.3 | 0.3% | 0 | 0 |
| 4.2.0 | 3 | 6.8 | 0.4% | 0 | 0 |
| 4.0.0 | 1 | 9.8 | 1.0% | 0 | 0 |