Web Cache Poisoning Vulnerability in Mastodon by Mastodon
CVE-2026-25540
6.5MEDIUM
What is CVE-2026-25540?
Mastodon, an open-source social network server utilizing ActivityPub, is vulnerable to web cache poisoning due to mishandling cached content. Enabled AUTHORIZED_FETCH allows the ActivityPub endpoints for pinned posts and featured hashtags to serve cached responses based on HTTP request accounts. This critical flaw lets responses intended for blocked users be shown to legitimate users or vice versa, leading to privacy issues. The vulnerability has been addressed in subsequent releases 4.3.19, 4.4.13, and 4.5.6.
Affected Version(s)
mastodon < 4.3.19 < 4.3.19
mastodon < 4.4.13 < 4.4.13
mastodon < 4.5.6 < 4.5.6
