PT-2026-2182 · Mastodon · Mastodon

·

CVE-2026-22246

·

Published

2026-01-08

·

Updated

2026-01-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions 4.3 through 4.3.16 Mastodon versions 4.4 through 4.4.10 Mastodon versions 4.5 through 4.5.3
Description Mastodon is a free, open-source social network server based on ActivityPub. A flaw exists in the code handling the download of lists of severed relationships for a particular event. This code does not verify the ownership of the list before returning the lost relationships. Consequently, any registered local user can access lists of lost followers and followed users resulting from any severance event, effectively enumerating severance events across the system. The leaked information does not include the name of the account that lost follows and followers.
Recommendations Update Mastodon to version 4.3.17 or later. Update Mastodon to version 4.4.11 or later. Update Mastodon to version 4.5.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2026-22246
CVE-2026-22246
GHSA-WW85-X9CP-5V24

Affected Products

Mastodon