SB20260728106 - Multiple vulnerabilities in Mastodon



SB20260728106 - Multiple vulnerabilities in Mastodon

Published: July 28, 2026

Security Bulletin ID SB20260728106
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Uncaught Exception (CVE-ID: CVE-2026-50129)

CWE-ID: CWE-248 - Uncaught Exception

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncaught exception handling in MATH_TRANSFORMER when processing malformed nodes. A remote attacker can post or send forged content to cause a denial of service.

The issue can affect the whole server or specific user-facing services depending on the action containing the malformed nodes and the services interacting with it.


2) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-50128)

CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof attribution domains.

The vulnerability exists due to improper signature verification in the attributionDomains JSON-LD term handling when processing signed Update activities. A remote attacker can modify the attributionDomains value of a legitimately signed Update activity to spoof attribution domains.

This can make an arbitrary webpage appear attributed to the target user for users on remote Mastodon servers.


Remediation

Install update from vendor's website.