Improper Enforcement of Behavioral Workflow in Mastodon - CVE-2026-41259
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass e-mail domain restrictions for signing up.
The vulnerability exists due to improper enforcement of behavioral workflow in e-mail address validation when processing sign-up requests. A remote attacker can use special characters in an e-mail address to bypass e-mail domain restrictions for signing up.
The issue can affect both blocked domains and allow-listed domains because some mail servers interpret certain characters differently.