Vulnerability in Mastodon Affects IPv4-Compatible IPv6 Address Handling
CVE-2026-72916
What is CVE-2026-72916?
Mastodon, the open-source social media server, has a vulnerability that pertains to its handling of IPv4-compatible IPv6 addresses. Specifically, prior to certain versions, the application incorrectly normalized these addresses, enabling attackers to supply omitted addresses. This could potentially allow malicious users to bypass the ALLOWED_PRIVATE_ADDRESSES protection, resulting in HTTP requests being sent to loopback interfaces and possibly gaining access to sensitive internal resources and services. This vulnerability is addressed in recent releases, ensuring greater security against such oversights.
Affected Version(s)
mastodon < 4.4.21 < 4.4.21
mastodon >= 4.5.0-beta.1, < 4.5.14 < 4.5.0-beta.1, 4.5.14
mastodon >= 4.6.0-beta.1, < 4.6.4 < 4.6.0-beta.1, 4.6.4
