Improper Input Validation in Mastodon Social Network Server
CVE-2026-46348
8.7HIGH
What is CVE-2026-46348?
Mastodon, a free and open-source social network server utilizing ActivityPub, contains a vulnerability wherein an incomplete list of disallowed IP address ranges exposes it to risks. Versions prior to 4.5.10, 4.4.17, and 4.3.23 fail to adequately block specific local IP ranges, enabling attackers to perform HTTP requests to loopback interfaces. This could allow unauthorized access to private resources and services, compromising the security integrity of the platform.
Affected Version(s)
mastodon >= 4.5.0-beta.1, < 4.5.10
