Insecure Direct Object Reference in Mastodon by Mastodon
CVE-2026-23964
What is CVE-2026-23964?
Mastodon, a free and open-source social network server based on ActivityPub, is vulnerable to an insecure direct object reference in its web push subscription update endpoint. Prior to the corrected versions (4.5.5, 4.4.12, and 4.3.18), this vulnerability enables any authenticated user to manipulate another user's push subscription by guessing or accessing the numeric subscription ID. This exploitation can disrupt notifications for victims by altering their push subscription settings, including filtering preferences and notification types. Furthermore, the endpoint leakage allows unauthorized access to the web push subscription endpoint without exposing sensitive keypair information, thereby increasing the security risks for affected users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mastodon < 4.3.18 < 4.3.18
mastodon >= 4.4.0, < 4.4.12 < 4.4.0, 4.4.12
mastodon >= 4.5.0, < 4.5.5 < 4.5.0, 4.5.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
