๐Ÿ” CVE Alert

CVE-2026-41259

UNKNOWN 0.0

Mastodon: Insufficient verification of email addresses

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.

CWE CWE-841
Vendor mastodon
Product mastodon
Published Apr 23, 2026
Last Updated Apr 23, 2026
Stay Ahead of the Next One

Get instant alerts for mastodon mastodon

Be the first to know when new unknown vulnerabilities affecting mastodon mastodon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mastodon / mastodon
< 4.3.22 >= 4.4.0-beta.1, < 4.4.16 >= 4.5.0-beta.1, < 4.5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mastodon/mastodon/security/advisories/GHSA-5r37-qpwq-2jhh