Skip to content

Known CVE

Mastodon - Open Redirect

Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.

CVE-2026-33868

Medium2026CVSS 4.3CWE-601

cve2026 · mastodon · open-redirect · vuln · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website