Spoofing Vulnerability in Mastodon Social Network Server
CVE-2026-48028

6.5MEDIUM

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-48028?

Mastodon, an open-source social network server, prior to certain versions, had a flaw in the normalization of incoming activities that were signed with Linked-Data Signatures. This weakness could be exploited by attackers to remove JSON entries from valid signed activities from legitimate third-party actors. The issue has been addressed in subsequent updates, specifically in versions 4.5.10, 4.4.17, and 4.3.23, enhancing the protection against this class of spoofing attack.

Affected Version(s)

mastodon >= 4.5.0-beta.1, < 4.5.10 < 4.5.0-beta.1, 4.5.10

mastodon >= 4.4.0-beta.1, < 4.4.17 < 4.4.0-beta.1, 4.4.17

mastodon < 4.3.23 < 4.3.23

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.