CVE-2026-72916 is a vulnerability in Mastodon, a free, open-source social network server. An attacker could supply an address in an omitted range to bypass the ALLOWED_PRIVATE_ADDRESSES protection and make Mastodon send HTTP requests to loopback interfaces, potentially accessing private resources and services. This issue is fixed in versions 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1.
CVE-2026-72915 is a vulnerability in Mastodon, a free, open-source social network server. From versions 4.6.0-beta.1 to 4.6.4 and 4.7.0-beta.1, any logged-in local user could access personally identifying information about another local user in a collection due to a policy issue in the app/controllers/admin/collections_controller.rb file. The exposed data included the other user's current email address an [truncated]
CVE-2026-72914 is a high-severity vulnerability in Mastodon, a free, open-source social network server. The vulnerability affects versions prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1. It allows anonymous callers to submit parameters that cause long-running SQL queries, exhausting server resources. This issue is fixed in the mentioned versions.
CVE-2026-47777 is a HIGH severity vulnerability in Mastodon, a free, open-source social network server. An attacker could bypass the check for remote accounts' consent to be featured in a remote Collection, potentially allowing them to fake consent and manipulate Collection items. This vulnerability affects Mastodon servers running the main branch or nightly builds with the experimental 'Collections' feat [truncated]