CVE-2026-50128 Details
Description
Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their articles. To prevent false attribution claims, Mastodon uses the attributionDomains JSON-LD term, however, an error in how it is defined makes Linked Data Signatures on the toot:attributionDomains property ineffective. An attacker can arbitrarily modify the attributionDomains value of a legitimately signed Update activity and bypass Mastodon’s signature verification. This vulnerability is fixed in 4.5.11 and 4.4.18.
A vulnerability exists in Mastodon versions prior to 4.5.11 and 4.4.18, allowing attackers to spoof attribution domains in signed Update activities. This issue arises from a flaw in how the attributionDomains JSON-LD term is defined, rendering Linked Data Signatures ineffective. As a result, an attacker can arbitrarily modify the attributionDomains value, bypassing Mastodon's signature verification and potentially misattributing web pages to users on remote Mastodon servers.
Users can upgrade to Mastodon versions 4.5.11 or 4.4.18 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gogs/gogs/security/advisories/GHSA-pwx3-qcgw-vh7h | CISA-ADP | |
| https://github.com/mastodon/mastodon/security/advisories/GHSA-rwcw-vq68-g34p | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mastodon | < 4.5.11 (semver) < 4.4.18 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion