Improper Verification of Cryptographic Signature in Mastodon - CVE-2026-50128

 

Improper Verification of Cryptographic Signature in Mastodon - CVE-2026-50128

Published: July 28, 2026


Vulnerability identifier: #VU139919
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50128
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof attribution domains.

The vulnerability exists due to improper signature verification in the attributionDomains JSON-LD term handling when processing signed Update activities. A remote attacker can modify the attributionDomains value of a legitimately signed Update activity to spoof attribution domains.

This can make an arbitrary webpage appear attributed to the target user for users on remote Mastodon servers.


Affected software

Mastodon

How to mitigate CVE-2026-50128

Install security update from vendor's website.

Mastodon - addressed in versions 4.4.18, 4.5.11

External References

Related Security Bulletins