joinmastodon
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 22, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Mastodon: Insufficient verification of email addresses
Mastodon has a denial of service for quote authorization
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
Mastodon has SSRF via unvalidated FASP Provider base_url
Mastodon may allow unconfirmed FASP to make subscriptions
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
Mastodon has insufficient access control to push notification settings
Mastodon missing length limits on list names, filter names, and filter keywords
Mastodon vulnerable to Denial of Service from a single post (client/server)
Mastodon may allow a remote suspension bypass
Monitor joinmastodon in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.