CVE-2026-27468General(joinmastodon / mastodon)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to backfill content did not check properly whether the FASP was actually approved. This only affects Mastodon servers that have opted in to testing the experimental FASP feature by setting the environment variable `EXPERIMENTAL_FEATURES` to a value including `fasp`. An attacker can make subscriptions and request content backfill without approval by an administrator. Done once, this leads to minor information leak of URIs that are publicly available anyway. But done several times this is a serious vector for DOS, putting pressure on the sidekiq worker responsible for the `fasp` queue. The fix is included in the 4.4.14 and 4.5.7 releases. Admins that are actively testing the experimental "fasp" feature should update their systems. Servers not using the experimental feature flag `fasp` are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mastodon

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
mastodon

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 102-2402-2502-26
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-242
General2
2026-02-251
General1
2026-02-261
Disclosure1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27468 - High Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through ... https://www.thehackerwire.com/vulnerability/CVE-2026-27468/ https://t.co/8YhXOfNGoh

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑27468) affecting Mastodon versions 4.4.0‑4.4.13 and 4.5.0‑… has been disclosed, with details available via the provided link.

    0000035
    115 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27468 Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through … https://www.cve.org/CVERecord?id=CVE-2026-27468

    Post summary

    The post references CVE-2026-27468 affecting Mastodon versions 4.4.0 onward, noting a registration issue requiring manual admin approval, but provides no PoC, exploit, patch, or active exploitation details.

    00000144
    56.6K followersView on X
  • ✨_geeknik_//✨@geeknik
    General

    Experimental features can introduce unexpected security issues. Take these 2 bugs in Mastodon for example. CVE-2026-27477: https://github.com/mastodon/mastodon/security/advisories/GHSA-46w6-g98f-wxqm CVE-2026-27468: https://github.com/mastodon/mastodon/security/advisories/GHSA-qgmm-vr4c-ggjg

    Post summary

    The post references two Mastodon CVEs via GitHub advisory links but provides no further details or actionable information.

    00000129
    20.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27468 Mastodon FASP Subscription Vulnerability in Versions 4.4.0-4.4.13 and 4.5.0-4.5.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27468

    Post summary

    The text announces CVE-2026-27468 affecting specific Mastodon versions and links to a vulnerability database entry, but provides no further technical, exploit, or mitigation details.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoinmastodonmastodon---

Explore more