Spoofing Vulnerability in Mastodon Social Network Server
CVE-2026-48028
6.5MEDIUM
What is CVE-2026-48028?
Mastodon, an open-source social network server, prior to certain versions, had a flaw in the normalization of incoming activities that were signed with Linked-Data Signatures. This weakness could be exploited by attackers to remove JSON entries from valid signed activities from legitimate third-party actors. The issue has been addressed in subsequent updates, specifically in versions 4.5.10, 4.4.17, and 4.3.23, enhancing the protection against this class of spoofing attack.
Affected Version(s)
mastodon >= 4.5.0-beta.1, < 4.5.10 < 4.5.0-beta.1, 4.5.10
mastodon >= 4.4.0-beta.1, < 4.4.17 < 4.4.0-beta.1, 4.4.17
mastodon < 4.3.23 < 4.3.23
