Input validation error in Mastodon - CVE-2026-48028
Published: May 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to selectively hide contents of a signed activity.
The vulnerability exists due to improper input validation in incoming activity normalization for Linked-Data Signatures when processing signed activities from a third-party actor. A remote attacker can remove JSON entries from a valid signed activity to selectively hide contents of a signed activity.
Exploitation requires access to the original signed activity object.