LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33868

CVE-2026-33868 - Vulnerability Analysis

MediumCVSS: 4.3

Last Updated: March 27, 2026

Mastodon - Open Redirect

Published: March 27, 2026Updated: March 27, 2026PoC AvailableRemote Exploitable

Overview

Mastodon versions < 4.5.8, < 4.4.15, and < 4.3.21 contain an Open Redirect vulnerability in the /web/* route due to improper handling of URL-encoded path segments, allowing unauthenticated attackers to redirect users.

Severity & Score

Severity: Medium
CVSS Score: 4.3

Impact

Redirect users to external domain.

Mitigation

Update Mastodon to versions 4.5.8, 4.4.15, 4.3.21.

Details

CVE ID
CVE-2026-33868
Severity
Medium
CVSS Score
4.3
Type
open_redirect
Status
new

CWE

  • CWE-601

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N