Known CVE
Mastodon - Open Redirect
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
CVE-2026-33868
Medium2026CVSS 4.3CWE-601
cve2026 · mastodon · open-redirect · vuln · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website