CVE Explorer
CVE-2026-23961
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under certain circumstances, previously-unknown posts from suspended users can be processed. This issue allows old posts from suspended users to occasionally end up on timelines on all Mastodon versions. Additi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mastodon","vendor":"mastodon","versions":[{"status":"affected","version":"< 4.3.18"},{"status":"affected","version":">= 4.4.0, < 4.4.12"},{"status":"affected","version":">= 4.5.0, < 4.5.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/mastodon/mastodon/releases/tag/v4.3.18","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/releases/tag/v4.3.18"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/references/1
{"name":"https://github.com/mastodon/mastodon/releases/tag/v4.4.12","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/releases/tag/v4.4.12"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/references/2
{"name":"https://github.com/mastodon/mastodon/releases/tag/v4.5.5","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/releases/tag/v4.5.5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/references/3
{"name":"https://github.com/mastodon/mastodon/security/advisories/GHSA-5h2f-wg8j-xqwp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-5h2f-wg8j-xqwp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d529b96a2c5491ec51207010eb32b434ed5de73cdd443fb366611752fa028a82 · sha256:701d71934d4e3106… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.