CVE Explorer
CVE-2026-22246
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of severed relationships for a particular event fails to check the owner of the list before returning the lost relationships. Any registered local user can access the list of lost followers and followed users caused by any seve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mastodon","vendor":"mastodon","versions":[{"status":"affected","version":"< 4.3.17"},{"status":"affected","version":">= 4.4.0-beta.1, < 4.4.11"},{"status":"affected","version":">= 4.5.0-beta.1, < 4.5.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-201","description":"CWE-201: Insertion of Sensitive Information Into Sent Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/mastodon/mastodon/commit/68e30985ca7afdb89af1b2e9dc962e1993dc8076","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/68e30985ca7afdb89af1b2e9dc962e1993dc8076"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/references/1
{"name":"https://github.com/mastodon/mastodon/commit/b2bcd34486fd6681cc0f30028086ef0f47282adf","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/b2bcd34486fd6681cc0f30028086ef0f47282adf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/references/2
{"name":"https://github.com/mastodon/mastodon/commit/c1fb6893c5175d74c074f6f786d504c8bc610d57","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/c1fb6893c5175d74c074f6f786d504c8bc610d57"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/references/3
{"name":"https://github.com/mastodon/mastodon/security/advisories/GHSA-ww85-x9cp-5v24","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-ww85-x9cp-5v24"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3cb49a07f8c70339836f2addb784dd42893d4d5f9bc6559bba94f8f3c17da7c9 · sha256:d2e2cf339e2c29b4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.