
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46349 is a Linked-Data (LD) Signature bypass vulnerability in Mastodon, the open-source ActivityPub-based social network server, tracked as "LD-Signature Bypass via JSON-LD Named-Graph Restructuring." It affects Mastodon versions prior to 4.5.10, 4.4.17, and 4.3.23, and was published on June 24, 2026. The flaw allows unauthenticated remote attackers to re-arrange valid signed JSON-LD activities from third-party actors so they are processed differently by the target server. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). Mastodon's normalization process for incoming ActivityPub activities signed with Linked-Data Signatures does not adequately canonicalize or protect the JSON-LD structure before verifying the signature, leaving it susceptible to named-graph restructuring attacks. An attacker can take a legitimately signed JSON-LD activity from a third-party actor, re-arrange its structure (e.g., by manipulating named graphs), and submit it to a Mastodon instance where it will pass signature verification but be interpreted differently than originally intended. No authentication or user interaction is required to exploit this vulnerability (GitHub Advisory).
The primary confirmed impact is the ability for an attacker to re-issue retracted Announce (boost) activities on behalf of a third-party Mastodon user without their knowledge or involvement, effectively spoofing social actions. The impact against other ActivityPub implementations is harder to quantify but is assessed as similarly limited in scope. There is no confidentiality or availability impact; the integrity impact is low and confined to the ActivityPub federation layer (GitHub Advisory).
/inbox or actor-specific inbox endpoints containing JSON-LD @graph or named-graph constructs that differ structurally from standard Mastodon-generated activities.Mastodon has released patched versions 4.5.10, 4.4.17, and 4.3.23 that address the insufficient normalization of incoming LD-Signature-signed activities. Administrators should upgrade to one of these fixed versions as soon as possible. No configuration-based workaround is documented; upgrading is the only recommended remediation (GitHub Advisory).
The vulnerability was reported by Savio of Doyensec in collaboration with Claude (Anthropic's AI) and Anthropic Research, making it notable as an AI-assisted security discovery. The advisory was published by Mastodon maintainer renchap on May 20, 2026. No significant broader media coverage or community controversy has been identified beyond the standard security advisory process (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."