CVE-2023-42451: Joinmastodon Mastodon

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.

Affected products

  • Joinmastodon Mastodon: before 3.5.14 (fixed in 3.5.14); from 4.0.0, before 4.0.10 (fixed in 4.0.10); from 4.1.0, before 4.1.8 (fixed in 4.1.8); version 4.2.0 only

Published 2023-09-19. Last modified 2026-06-17.