Improper Validation of Syntactic Correctness of Input in Mastodon - #VU139921

 

Improper Validation of Syntactic Correctness of Input in Mastodon - #VU139921

Published: July 28, 2026


Vulnerability identifier: #VU139921
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1286
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access otherwise private resources and services.

The vulnerability exists due to improper validation of syntactic correctness of input in SSRF protection for outbound HTTP requests when processing user-provided domains containing IPv4-compatible IPv6 addresses. A remote attacker can supply a crafted address to make Mastodon perform HTTP requests against loopback interfaces to access otherwise private resources and services.

This can only be exploited on systems that support IPv4-compatible IPv6 addresses.


Affected software

Mastodon

Remediation

Install security update from vendor's website.

Mastodon - addressed in versions 4.4.21, 4.5.14, 4.6.4

External References

Related Security Bulletins