CVE-2025-27399: Mastodon's domain blocks & rationales ignore user approval when visibility set as "users"
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.1.23 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.2.16 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27399?
CVE-2025-27399 is considered a medium severity vulnerability due to unauthorized access to block reasons by unapproved users.
How do I fix CVE-2025-27399?
To fix CVE-2025-27399, update your Mastodon installation to versions 4.1.23, 4.2.16, or 4.3.4 or later.
What are the affected versions for CVE-2025-27399?
CVE-2025-27399 affects Mastodon versions prior to 4.1.23, 4.2.16, and 4.3.4.
What is the impact of CVE-2025-27399 on users?
The impact of CVE-2025-27399 allows unapproved users to see domain block reasons, which may expose sensitive information.
Is there a workaround for CVE-2025-27399 if I cannot update?
There is no specific workaround for CVE-2025-27399, so updating to a patched version is strongly recommended.