
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48028 is a spoofing vulnerability in Mastodon, the open-source ActivityPub-based social network server, where insufficient normalization of incoming activities signed with Linked-Data Signatures allows attackers to remove JSON entries from valid signed activities originating from third-party actors. Published on June 24, 2026, it affects Mastodon versions prior to 4.3.23, 4.4.0-beta.1 through 4.4.17, and 4.5.0-beta.1 through 4.5.10. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is classified as CWE-354 (Improper Validation of Integrity Check Value), specifically in Mastodon's normalization process for incoming ActivityPub activities signed with Linked-Data Signatures. When Mastodon normalizes a signed activity, it does not adequately verify that all JSON entries are protected by the signature, enabling an attacker who possesses a valid signed activity to strip out specific JSON fields while the server still accepts the modified activity as legitimate. Exploitation requires the attacker to first obtain a copy of the original signed activity object — achievable through ActivityPub's inbox forwarding mechanism or via relay subscriptions — and then selectively remove JSON entries before forwarding the tampered activity to a target Mastodon server (GitHub Advisory).
Successful exploitation allows an attacker to selectively hide or remove content from signed ActivityPub activities, causing a Mastodon server to process an incomplete or manipulated activity as if it were the full, authentic original. This primarily affects integrity and availability — an attacker could suppress specific fields (e.g., content, recipients, or metadata) in federated activities, potentially disrupting federation behavior or misrepresenting the original author's intent. Confidentiality is not directly impacted, and the scope is limited to the affected Mastodon instance's federation processing (GitHub Advisory).
Mastodon has released patched versions 4.5.10, 4.4.17, and 4.3.23 that address this vulnerability. Administrators should upgrade to one of these fixed versions as soon as possible. No configuration-based workarounds have been published; upgrading is the only recommended remediation (GitHub Advisory).
The vulnerability was reported by security researcher tesaguri and the advisory was published by Mastodon maintainer renchap on May 20, 2026, with the CVE assigned on June 24, 2026. No significant broader media coverage or notable community commentary beyond the official advisory has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."