Outbound Request Vulnerability in Mastodon Social Network Server
CVE-2026-22245
What is CVE-2026-22245?
Mastodon, an open-source social networking server, faces an outbound request vulnerability that allows an attacker to leverage improperly restricted IP address ranges. This flaw enables unauthorized requests to local network hosts, potentially exposing sensitive internal services. By exploiting this, attackers can bypass Mastodon's existing protections against local IP access, urging users to update to secure versions to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mastodon < 4.2.29 < 4.2.29
mastodon >= 4.3.0-beta.1, < 4.3.17 < 4.3.0-beta.1, 4.3.17
mastodon >= 4.4.0-beta.1, < 4.4.11 < 4.4.0-beta.1, 4.4.11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
