HarborGuard / CVE
Back to search
HIGHCVE-2026-41259Published Modified CNA GitHub_M

CVE-2026-41259: Mastodon: Insufficient verification of email addresses

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.

Metrics

CVSS v4.0
8.2
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • mastodon / mastodon
    < 4.3.22 · >= 4.4.0-beta.1, < 4.4.16 · >= 4.5.0-beta.1, < 4.5.9
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N