CVE-2026-41259: Mastodon: Insufficient verification of email addresses
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted differently by some mailing servers. This vulnerability is fixed in v4.5.9, v4.4.16, and v4.3.22.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41259?
CVE-2026-41259 is classified with a high severity due to the potential for exploitation through insufficient email address verification.
How do I fix CVE-2026-41259?
To fix CVE-2026-41259, upgrade to Mastodon version 4.5.9, 4.4.16, or 4.3.22, where the issue has been addressed.
What type of vulnerability is CVE-2026-41259?
CVE-2026-41259 is a vulnerability related to insufficient verification of email addresses during user sign-up.
Who is affected by CVE-2026-41259?
Users of Mastodon versions prior to 4.5.9, 4.4.16, and 4.3.22 are affected by CVE-2026-41259.
What can happen if CVE-2026-41259 is exploited?
If exploited, CVE-2026-41259 can lead to unauthorized account creation and manipulation of user accounts.