CVE Explorer
CVE-2026-25540
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinned posts and featured hashtags have contents that depend on the account that signed the HTTP request. However, these contents are stored in an internal cache and reused with no regards to the signing actor. As a result, an empty response generated for
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mastodon","vendor":"mastodon","versions":[{"status":"affected","version":"< 4.3.19"},{"status":"affected","version":"< 4.4.13"},{"status":"affected","version":"< 4.5.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:248f7def99f9f22c62b640699c2b34180bb1a897b45e4866c826e48cebf4a8db · sha256:ea68a01e56564bcc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:248f7def99f9f22c62b640699c2b34180bb1a897b45e4866c826e48cebf4a8db · sha256:ea68a01e56564bcc… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-524","description":"CWE-524: Use of Cache Containing Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:248f7def99f9f22c62b640699c2b34180bb1a897b45e4866c826e48cebf4a8db · sha256:ea68a01e56564bcc… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/mastodon/mastodon/security/advisories/GHSA-ccpr-m53r-mfwr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-ccpr-m53r-mfwr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:248f7def99f9f22c62b640699c2b34180bb1a897b45e4866c826e48cebf4a8db · sha256:ea68a01e56564bcc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.