CVE-2026-41259: Joinmastodon Mastodon
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.
Affected products
- Joinmastodon Mastodon: before 4.3.22 (fixed in 4.3.22); from 4.4.0, before 4.4.16 (fixed in 4.4.16); from 4.5.0, before 4.5.9 (fixed in 4.5.9)
Published 2026-04-23. Last modified 2026-06-17.