Outbound Request Vulnerability in Mastodon Social Network Server
CVE-2026-22245

7.1HIGH

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
8 January 2026

What is CVE-2026-22245?

Mastodon, an open-source social networking server, faces an outbound request vulnerability that allows an attacker to leverage improperly restricted IP address ranges. This flaw enables unauthorized requests to local network hosts, potentially exposing sensitive internal services. By exploiting this, attackers can bypass Mastodon's existing protections against local IP access, urging users to update to secure versions to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

mastodon < 4.2.29 < 4.2.29

mastodon >= 4.3.0-beta.1, < 4.3.17 < 4.3.0-beta.1, 4.3.17

mastodon >= 4.4.0-beta.1, < 4.4.11 < 4.4.0-beta.1, 4.4.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.