CVE-2026-46348: Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was lacking an IP address range that can be used to reach local IP addresses. An attacker can use an IP address in the affected range to make Mastodon perform HTTP requests against loopback interfaces, potentially allowing access to otherwise private resources and services. This vulnerability is fixed in 4.5.10, 4.4.17, and 4.3.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.5.10 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.4.17 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.3.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46348?
The severity of CVE-2026-46348 is rated high with a CVSS score of 8.7.
What type of vulnerability is CVE-2026-46348?
CVE-2026-46348 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2026-46348?
To fix CVE-2026-46348, you should upgrade your Mastodon instance to versions 4.5.10, 4.4.17, or 4.3.23 or later.
What impact does CVE-2026-46348 have on end-users?
CVE-2026-46348 allows attackers to bypass restrictions and potentially access local IP addresses.
Which versions of Mastodon are affected by CVE-2026-46348?
CVE-2026-46348 affects Mastodon versions prior to 4.5.10, 4.4.17, and 4.3.23.