Improper Input Validation in Mastodon Social Network Server
CVE-2026-46348

8.7HIGH

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-46348?

Mastodon, a free and open-source social network server utilizing ActivityPub, contains a vulnerability wherein an incomplete list of disallowed IP address ranges exposes it to risks. Versions prior to 4.5.10, 4.4.17, and 4.3.23 fail to adequately block specific local IP ranges, enabling attackers to perform HTTP requests to loopback interfaces. This could allow unauthorized access to private resources and services, compromising the security integrity of the platform.

Affected Version(s)

mastodon >= 4.5.0-beta.1, < 4.5.10

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.