Vulnerability in Mastodon Affects IPv4-Compatible IPv6 Address Handling
CVE-2026-72916

6.3MEDIUM

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72916?

Mastodon, the open-source social media server, has a vulnerability that pertains to its handling of IPv4-compatible IPv6 addresses. Specifically, prior to certain versions, the application incorrectly normalized these addresses, enabling attackers to supply omitted addresses. This could potentially allow malicious users to bypass the ALLOWED_PRIVATE_ADDRESSES protection, resulting in HTTP requests being sent to loopback interfaces and possibly gaining access to sensitive internal resources and services. This vulnerability is addressed in recent releases, ensuring greater security against such oversights.

Affected Version(s)

mastodon < 4.4.21 < 4.4.21

mastodon >= 4.5.0-beta.1, < 4.5.14 < 4.5.0-beta.1, 4.5.14

mastodon >= 4.6.0-beta.1, < 4.6.4 < 4.6.0-beta.1, 4.6.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.