CVE-2026-27477Disclosure(joinmastodon / mastodon)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, an unauthenticated attacker can register a FASP with an attacker-chosen `base_url` that includes or resolves to a local / internal address, leading to the Mastodon server making requests to that address. This only affects Mastodon servers that have opted in to testing the experimental FASP feature by setting the environment variable `EXPERIMENTAL_FEATURES` to a value including `fasp`. An attacker can force the Mastodon server to make http(s) requests to internal systems. While they cannot control the full URL that is being requested (only the prefix) and cannot see the result of those requests, vulnerabilities or other undesired behavior could be triggered in those systems. The fix is included in the 4.4.14 and 4.5.7 releases. Admins that are actively testing the experimental "fasp" feature should update their systems. Servers not using the experimental feature flag `fasp` are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mastodon

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-25)
  • 4 total mentions across 3 days

Affected systems

Products
mastodon

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-20: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 2Technical Details · 2026-02-25: 102-2002-2402-25
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-201
Disclosure1
2026-02-241
Disclosure1
2026-02-252
General2
Full discourse4 posts
  • ✨_geeknik_//✨@geeknik
    Disclosure

    Found a couple of bugs in Mastodon. One of them just received CVE-2026-27477. Keeping you safe, one line of code at a time.

    Post summary

    A new vulnerability (CVE-2026-27477) has been identified in Mastodon, but no further details, exploits, or mitigation steps are provided.

    02020276
    20.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27477 Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through … https://www.cve.org/CVERecord?id=CVE-2026-27477

    Post summary

    The text briefly references CVE‑2026‑27477 for Mastodon, noting a manual approval requirement for FASP registration, but provides no further details or actionable information.

    00000124
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27477 Server-Side Request Forgery in Mastodon FASP Registration for Experimental Features https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27477

    Post summary

    The post references CVE-2026-27477 as a Server‑Side Request Forgery in Mastodon’s FASP registration for experimental features, but provides no further details such as PoC, exploit, or patch information.

    0000033
    4.0K followersView on X
  • ✨_geeknik_//✨@geeknik
    Disclosure

    Experimental features can introduce unexpected security issues. Take these 2 bugs in Mastodon for example. CVE-2026-27477: https://github.com/mastodon/mastodon/security/advisories/GHSA-46w6-g98f-wxqm CVE-2026-27468: https://github.com/mastodon/mastodon/security/advisories/GHSA-qgmm-vr4c-ggjg

    Post summary

    The post references two newly disclosed Mastodon CVEs with links to GitHub advisories, but provides no further details on exploitation or mitigation.

    00000129
    20.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoinmastodonmastodon---

Explore more