SB20260728106 - Multiple vulnerabilities in Mastodon
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Uncaught Exception (CVE-ID: CVE-2026-50129)
CWE-ID: CWE-248 - Uncaught Exception
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncaught exception handling in MATH_TRANSFORMER when processing malformed
The issue can affect the whole server or specific user-facing services depending on the action containing the malformed nodes and the services interacting with it.
2) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-50128)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof attribution domains.
The vulnerability exists due to improper signature verification in the attributionDomains JSON-LD term handling when processing signed Update activities. A remote attacker can modify the attributionDomains value of a legitimately signed Update activity to spoof attribution domains.
This can make an arbitrary webpage appear attributed to the target user for users on remote Mastodon servers.
Remediation
Install update from vendor's website.