CVE-2026-46349
Mastodon vulnerability analysis and mitigation

Overview

CVE-2026-46349 is a Linked-Data (LD) Signature bypass vulnerability in Mastodon, the open-source ActivityPub-based social network server, tracked as "LD-Signature Bypass via JSON-LD Named-Graph Restructuring." It affects Mastodon versions prior to 4.5.10, 4.4.17, and 4.3.23, and was published on June 24, 2026. The flaw allows unauthenticated remote attackers to re-arrange valid signed JSON-LD activities from third-party actors so they are processed differently by the target server. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). Mastodon's normalization process for incoming ActivityPub activities signed with Linked-Data Signatures does not adequately canonicalize or protect the JSON-LD structure before verifying the signature, leaving it susceptible to named-graph restructuring attacks. An attacker can take a legitimately signed JSON-LD activity from a third-party actor, re-arrange its structure (e.g., by manipulating named graphs), and submit it to a Mastodon instance where it will pass signature verification but be interpreted differently than originally intended. No authentication or user interaction is required to exploit this vulnerability (GitHub Advisory).

Impact

The primary confirmed impact is the ability for an attacker to re-issue retracted Announce (boost) activities on behalf of a third-party Mastodon user without their knowledge or involvement, effectively spoofing social actions. The impact against other ActivityPub implementations is harder to quantify but is assessed as similarly limited in scope. There is no confidentiality or availability impact; the integrity impact is low and confined to the ActivityPub federation layer (GitHub Advisory).

Exploitation steps

  1. Identify a target Mastodon instance: Locate a Mastodon server running a vulnerable version (< 4.5.10, < 4.4.17, or < 4.3.23) via public instance directories or ActivityPub federation metadata.
  2. Obtain a valid signed JSON-LD activity: Intercept or collect a legitimately signed Announce (boost) activity from a third-party actor that has since been retracted, using ActivityPub federation traffic or public activity streams.
  3. Restructure the JSON-LD named graph: Manipulate the JSON-LD structure of the signed activity — specifically re-arranging named graph components — in a way that alters how the activity will be interpreted by the target server while preserving the original cryptographic signature's validity under Mastodon's insufficient normalization.
  4. Submit the modified activity: Deliver the restructured activity to the target Mastodon instance via the ActivityPub inbox endpoint, bypassing signature verification.
  5. Achieve spoofed action: The target server processes the re-arranged activity as if it were a new, valid action (e.g., re-issuing a previously retracted boost) attributed to the original third-party actor (GitHub Advisory).

Indicators of compromise

  • Logs: Mastodon application logs showing unexpected or duplicate Announce (boost) activities from actors who had previously retracted them; ActivityPub inbox requests delivering JSON-LD payloads with unusual named-graph structures.
  • Network: Inbound HTTP POST requests to /inbox or actor-specific inbox endpoints containing JSON-LD @graph or named-graph constructs that differ structurally from standard Mastodon-generated activities.
  • Application Behavior: Boosts appearing in timelines from users who had previously undone those boosts, particularly from remote federated accounts, without corresponding new activity from those accounts.

Mitigation and workarounds

Mastodon has released patched versions 4.5.10, 4.4.17, and 4.3.23 that address the insufficient normalization of incoming LD-Signature-signed activities. Administrators should upgrade to one of these fixed versions as soon as possible. No configuration-based workaround is documented; upgrading is the only recommended remediation (GitHub Advisory).

Community reactions

The vulnerability was reported by Savio of Doyensec in collaboration with Claude (Anthropic's AI) and Anthropic Research, making it notable as an AI-assisted security discovery. The advisory was published by Mastodon maintainer renchap on May 20, 2026. No significant broader media coverage or community controversy has been identified beyond the standard security advisory process (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Mastodon vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47389HIGH8.6
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-50129HIGH7.5
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-48028MEDIUM6.5
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-50128MEDIUM5.3
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-46349MEDIUM5.3
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management