Improper Verification of Cryptographic Signature in Mastodon - CVE-2026-50128
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof attribution domains.
The vulnerability exists due to improper signature verification in the attributionDomains JSON-LD term handling when processing signed Update activities. A remote attacker can modify the attributionDomains value of a legitimately signed Update activity to spoof attribution domains.
This can make an arbitrary webpage appear attributed to the target user for users on remote Mastodon servers.