Web Cache Poisoning Vulnerability in Mastodon by Mastodon
CVE-2026-25540

6.5MEDIUM

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25540?

Mastodon, an open-source social network server utilizing ActivityPub, is vulnerable to web cache poisoning due to mishandling cached content. Enabled AUTHORIZED_FETCH allows the ActivityPub endpoints for pinned posts and featured hashtags to serve cached responses based on HTTP request accounts. This critical flaw lets responses intended for blocked users be shown to legitimate users or vice versa, leading to privacy issues. The vulnerability has been addressed in subsequent releases 4.3.19, 4.4.13, and 4.5.6.

Affected Version(s)

mastodon < 4.3.19 < 4.3.19

mastodon < 4.4.13 < 4.4.13

mastodon < 4.5.6 < 4.5.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.