CVE-2026-22245
Last modified
CVE-2026-22245 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_PRIVATE_ADDRESSES`) to avoid the "confused deputy" problem. The list of disallowed IP address ranges was lacking some IP address ranges that can be used to reach local IP addresses. An attacker can use an IP address in the affected ranges to make Mastodon perform HTTP requests against loopback or local network hosts, potentially allowing access to otherwise private resources and services. This is fixed in Mastodon v4.5.4, v4.4.11, v4.3.17 and v4.2.29.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | < 4.2.29 |
| Joinmastodon | Mastodon | >= 4.3.0, < 4.3.17 |
| Joinmastodon | Mastodon | >= 4.4.0, < 4.4.11 |
| Joinmastodon | Mastodon | >= 4.5.0, < 4.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22245?
How severe is CVE-2026-22245?
How do I fix CVE-2026-22245?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2224A vulnerability was detected in code-projects Online Reviewe…5.4
- CVE-2026-22240The vulnerability exists in BLUVOYIX due to an improper pass…7.5
- CVE-2026-22241The Open eClass platform (formerly known as GUnet eClass) is…7.2
- CVE-2026-22242CoreShop is a Pimcore enhanced eCommerce solution. Prior to …4.9
- CVE-2026-22243EGroupware is a Web based groupware server written in PHP. A…8.8
- CVE-2026-22244OpenMetadata is a unified metadata platform. Versions prior …7.2
- CVE-2026-22246Mastodon is a free, open-source social network server based …4.3
- CVE-2026-22247GLPI is a free asset and IT management software package. Fro…9.1
- CVE-2026-22248GLPI is an open-source asset and IT management software pack…8.8
- CVE-2026-22249Docmost is an open-source collaborative wiki and documentati…9.8
- CVE-2026-2225A flaw has been found in itsourcecode News Portal Project 1.…9.8
- CVE-2026-22250wlc is a Weblate command-line client using Weblate's REST AP…5.5
Are you affected by CVE-2026-22245?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
