Improper Validation of Syntactic Correctness of Input in Mastodon - #VU139921
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to access otherwise private resources and services.
The vulnerability exists due to improper validation of syntactic correctness of input in SSRF protection for outbound HTTP requests when processing user-provided domains containing IPv4-compatible IPv6 addresses. A remote attacker can supply a crafted address to make Mastodon perform HTTP requests against loopback interfaces to access otherwise private resources and services.
This can only be exploited on systems that support IPv4-compatible IPv6 addresses.