CVE-2026-48028: Mastodon: Removal of integrity-protected JSON entries from signed activities
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing threat actors to remove JSON entries from valid signed activities from a third-party actor. This vulnerability is fixed in 4.5.10, 4.4.17, and 4.3.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.5.10 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.4.17 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.3.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48028?
The severity of CVE-2026-48028 is classified as medium with a score of 6.5.
How do I fix CVE-2026-48028?
To fix CVE-2026-48028, upgrade to Mastodon versions 4.5.10, 4.4.17, or 4.3.23 or later.
What type of threat does CVE-2026-48028 expose Mastodon users to?
CVE-2026-48028 exposes Mastodon users to informational spoofing attacks due to inadequate protection of signed activities.
Which versions of Mastodon are affected by CVE-2026-48028?
Versions of Mastodon prior to 4.5.10, 4.4.17, and 4.3.23 are affected by CVE-2026-48028.
What kind of activities are impacted by CVE-2026-48028?
CVE-2026-48028 impacts the normalization of incoming activities signed with Linked-Data Signatures.