CVE Explorer
CVE-2026-27477
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with an attacker-chosen `base_url` that includes or resolves to a local / internal address, leading to the Mastodon server making requests to that address. This only affects Mastodon servers that have opted in to testing the experimental FASP feature by
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mastodon","vendor":"mastodon","versions":[{"status":"affected","version":">= 4.4.0, < 4.4.14"},{"status":"affected","version":">= 4.5.0, < 4.5.7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2fa40a0b5bf0e0a34b48d6d04e51ea201a64c95147c9733e2ed13a6d3689556d · sha256:352307bff80d4d7c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":4.6,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2fa40a0b5bf0e0a34b48d6d04e51ea201a64c95147c9733e2ed13a6d3689556d · sha256:352307bff80d4d7c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2fa40a0b5bf0e0a34b48d6d04e51ea201a64c95147c9733e2ed13a6d3689556d · sha256:352307bff80d4d7c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/mastodon/mastodon/commit/7b85d2182361e68d51d9a02f94fb1070b5f503b1","tags":["x_refsource_MISC"],"url":"https://github.com/mastodon/mastodon/commit/7b85d2182361e68d51d9a02f94fb1070b5f503b1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2fa40a0b5bf0e0a34b48d6d04e51ea201a64c95147c9733e2ed13a6d3689556d · sha256:352307bff80d4d7c… · /containers/cna/references/1
{"name":"https://github.com/mastodon/mastodon/security/advisories/GHSA-46w6-g98f-wxqm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-46w6-g98f-wxqm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2fa40a0b5bf0e0a34b48d6d04e51ea201a64c95147c9733e2ed13a6d3689556d · sha256:352307bff80d4d7c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.