CVE-2026-46348 | Mastodon up to 4.5.9 Loopback Interface server-side request forgery (GHSA-crr4-7rm4-8gpw)

SecurityVulns

A vulnerability described as critical has been identified in Mastodon up to 4.5.9. The affected element is an unknown function of the component Loopback Interface Handler. Executing a manipulation can lead to server-side request forgery.

This vulnerability appears as CVE-2026-46348. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More