{"id":"CVE-2023-42451","summary":"Mastodon Invalid Domain Name Normalization vulnerability","details":"Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.","aliases":["BIT-mastodon-2023-42451","GHSA-v3xf-c9qf-j667"],"modified":"2026-04-02T09:26:31.823096Z","published":"2023-09-19T15:56:46.962Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42451.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-706"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42451.json"},{"type":"ADVISORY","url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-v3xf-c9qf-j667"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42451"},{"type":"FIX","url":"https://github.com/mastodon/mastodon/commit/eeab3560fc0516070b3fb97e089b15ecab1938c8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mastodon/mastodon","events":[{"introduced":"0"},{"fixed":"75346a71f7f4f0a3deb2841c19e6105a06f98f1e"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.5.14"}]}},{"type":"GIT","repo":"https://github.com/mastodon/mastodon","events":[{"introduced":"fb389bd73c8a4bc2924496f6041c8eee27572d21"},{"fixed":"3d8ae6ab739ab1222546923c8df703260285fbc3"}],"database_specific":{"versions":[{"introduced":"4.0.0"},{"fixed":"4.0.10"}]}},{"type":"GIT","repo":"https://github.com/mastodon/mastodon","events":[{"introduced":"61c5dfb9295ea66c376c452a7ef7379e8c562416"},{"fixed":"46bd58f74d11591a0180319285b0c79b2212ef69"}],"database_specific":{"versions":[{"introduced":"4.1.0"},{"fixed":"4.1.8"}]}},{"type":"GIT","repo":"https://github.com/mastodon/mastodon","events":[{"introduced":"dab54ccbba3721382241725bb1c1159d24b5aab2"},{"fixed":"f4b780ba22d0256770766185cee5f8fcc5585c95"}],"database_specific":{"versions":[{"introduced":"4.2.0-beta1"},{"fixed":"4.2.0-rc2"}]}}],"versions":["v0.1.0","v0.1.1","v0.1.2","v0.6","v0.7","v0.8","v0.9","v0.9.9","v1.0","v1.1","v1.1.1","v1.1.2","v1.2","v1.2.1","v1.2.2","v1.3","v1.3.1","v1.3.2","v1.3.3","v1.4.1","v1.4.2","v1.4.3","v1.4.4","v1.4.5","v1.4.6","v1.4.7","v1.4rc1","v1.4rc2","v1.4rc3","v1.4rc4","v1.4rc5","v1.4rc6","v1.5.0","v1.5.0rc1","v1.5.0rc2","v1.5.0rc3","v1.5.1","v1.6.0","v1.6.0rc1","v1.6.0rc2","v1.6.0rc3","v1.6.0rc4","v1.6.0rc5","v1.6.1","v2.0.0","v2.0.0rc1","v2.0.0rc2","v2.0.0rc3","v2.0.0rc4","v2.1.0","v2.1.0rc1","v2.1.0rc2","v2.1.0rc3","v2.1.0rc4","v2.1.0rc5","v2.1.0rc6","v2.1.1","v2.1.2","v2.1.3","v2.2.0","v2.2.0rc1","v2.2.0rc2","v2.3.0","v2.3.0rc1","v2.3.0rc2","v2.3.0rc3","v2.3.1","v2.3.1rc1","v2.3.1rc2","v2.3.1rc3","v2.3.2","v2.3.2rc1","v2.3.2rc2","v2.3.2rc3","v2.3.2rc4","v2.3.2rc5","v2.3.3","v2.4.0","v2.4.0rc1","v2.4.0rc2","v2.4.0rc3","v2.4.0rc4","v2.4.0rc5","v2.4.1","v2.4.1rc1","v2.4.1rc2","v2.4.1rc3","v2.4.1rc4","v2.4.2","v2.4.2rc1","v2.4.2rc2","v2.4.2rc3","v2.4.3","v2.4.3rc1","v2.4.3rc2","v2.4.3rc3","v2.4.4","v2.4.5","v2.5.0","v2.5.0rc1","v2.5.0rc2","v2.5.1","v2.5.2","v2.6.0","v2.6.0rc1","v2.6.0rc2","v2.6.0rc3","v2.6.0rc4","v2.6.1","v2.6.2","v2.6.3","v2.6.4","v2.6.5","v2.7.0","v2.7.0rc1","v2.7.0rc2","v2.7.0rc3","v2.7.1","v2.7.2","v2.7.3","v2.7.4","v2.8.0","v2.8.0rc1","v2.8.0rc2","v2.8.0rc3","v2.8.1","v2.8.2","v2.8.3","v2.8.4","v2.9.0","v2.9.0rc1","v2.9.0rc2","v2.9.1","v2.9.2","v2.9.3","v2.9.4","v3.0.0","v3.0.0rc1","v3.0.0rc2","v3.0.0rc3","v3.0.1","v3.0.2","v3.1.0","v3.1.0rc1","v3.1.0rc2","v3.1.1","v3.1.2","v3.1.3","v3.1.4","v3.1.5","v3.2.0","v3.2.0rc1","v3.2.0rc2","v3.2.1","v3.2.2","v3.3.0","v3.3.0rc1","v3.3.0rc2","v3.3.0rc3","v3.3.1","v3.3.2","v3.3.3","v3.4.0","v3.4.0rc1","v3.4.0rc2","v3.4.1","v3.4.10","v3.4.2","v3.4.3","v3.4.4","v3.4.5","v3.4.6","v3.4.7","v3.4.8","v3.4.9","v3.5.0","v3.5.0rc1","v3.5.0rc2","v3.5.0rc3","v3.5.1","v3.5.10","v3.5.11","v3.5.12","v3.5.13","v3.5.2","v3.5.3","v3.5.4","v3.5.5","v3.5.6","v3.5.7","v3.5.8","v3.5.9","v4.0.0","v4.0.0rc1","v4.0.0rc2","v4.0.0rc3","v4.0.0rc4","v4.0.1","v4.0.10","v4.0.11","v4.0.12","v4.0.13","v4.0.14","v4.0.15","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.0rc1","v4.1.0rc2","v4.1.0rc3","v4.1.1","v4.1.10","v4.1.11","v4.1.12","v4.1.13","v4.1.14","v4.1.15","v4.1.16","v4.1.17","v4.1.18","v4.1.19","v4.1.2","v4.1.20","v4.1.21","v4.1.22","v4.1.23","v4.1.24","v4.1.25","v4.1.3","v4.1.4","v4.1.5","v4.1.6","v4.1.7","v4.1.8","v4.1.9","v4.2.0","v4.2.0-beta1","v4.2.0-beta2","v4.2.0-beta3","v4.2.0-rc1","v4.2.0-rc2","v4.2.1","v4.2.10","v4.2.11","v4.2.12","v4.2.13","v4.2.14","v4.2.15","v4.2.16","v4.2.17","v4.2.18","v4.2.19","v4.2.2","v4.2.20","v4.2.21","v4.2.22","v4.2.23","v4.2.24","v4.2.25","v4.2.26","v4.2.27","v4.2.28","v4.2.29","v4.2.3","v4.2.4","v4.2.5","v4.2.6","v4.2.7","v4.2.8","v4.2.9","v4.3.0","v4.3.0-beta.1","v4.3.0-beta.2","v4.3.0-rc.1","v4.3.1","v4.3.10","v4.3.11","v4.3.12","v4.3.13","v4.3.14","v4.3.15","v4.3.16","v4.3.17","v4.3.18","v4.3.19","v4.3.2","v4.3.20","v4.3.21","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.3.9","v4.4.0","v4.4.0-beta.1","v4.4.0-beta.2","v4.4.0-rc.1","v4.4.1","v4.4.10","v4.4.11","v4.4.12","v4.4.13","v4.4.14","v4.4.15","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.4.6","v4.4.7","v4.4.8","v4.4.9","v4.5.0","v4.5.0-beta.1","v4.5.0-beta.2","v4.5.0-rc.1","v4.5.0-rc.2","v4.5.0-rc.3","v4.5.1","v4.5.2","v4.5.3","v4.5.4","v4.5.5","v4.5.6","v4.5.7","v4.5.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42451.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/tootsuite/mastodon","events":[{"introduced":"0"},{"fixed":"75346a71f7f4f0a3deb2841c19e6105a06f98f1e"},{"introduced":"fb389bd73c8a4bc2924496f6041c8eee27572d21"},{"fixed":"3d8ae6ab739ab1222546923c8df703260285fbc3"},{"introduced":"61c5dfb9295ea66c376c452a7ef7379e8c562416"},{"fixed":"46bd58f74d11591a0180319285b0c79b2212ef69"},{"introduced":"0"},{"last_affected":"dab54ccbba3721382241725bb1c1159d24b5aab2"},{"introduced":"0"},{"last_affected":"facfec1ba36cee27f232ebff90b990933719235a"},{"introduced":"0"},{"last_affected":"f80f426c57d5a5e1d289372ef7c323741d27c768"},{"introduced":"0"},{"last_affected":"b90383d07388fe8513e59a6deb1a2391146c6561"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.5.14"},{"introduced":"4.0.0"},{"fixed":"4.0.10"},{"introduced":"4.1.0"},{"fixed":"4.1.8"},{"introduced":"0"},{"last_affected":"4.2.0-beta1"},{"introduced":"0"},{"last_affected":"4.2.0-beta2"},{"introduced":"0"},{"last_affected":"4.2.0-beta3"},{"introduced":"0"},{"last_affected":"4.2.0-rc1"}]}}],"versions":["v0.1.0","v0.1.1","v0.1.2","v0.6","v0.7","v0.8","v0.9","v0.9.9","v1.0","v1.1","v1.1.1","v1.1.2","v1.2","v1.2.1","v1.2.2","v1.3","v1.3.1","v1.3.2","v1.3.3","v1.4.1","v1.4.2","v1.4.3","v1.4.4","v1.4.5","v1.4.6","v1.4.7","v1.4rc1","v1.4rc2","v1.4rc3","v1.4rc4","v1.4rc5","v1.4rc6","v1.5.0","v1.5.0rc1","v1.5.0rc2","v1.5.0rc3","v1.5.1","v1.6.0","v1.6.0rc1","v1.6.0rc2","v1.6.0rc3","v1.6.0rc4","v1.6.0rc5","v1.6.1","v2.0.0","v2.0.0rc1","v2.0.0rc2","v2.0.0rc3","v2.0.0rc4","v2.1.0","v2.1.0rc1","v2.1.0rc2","v2.1.0rc3","v2.1.0rc4","v2.1.0rc5","v2.1.0rc6","v2.1.1","v2.1.2","v2.1.3","v2.2.0","v2.2.0rc1","v2.2.0rc2","v2.3.0","v2.3.0rc1","v2.3.0rc2","v2.3.0rc3","v2.3.1","v2.3.1rc1","v2.3.1rc2","v2.3.1rc3","v2.3.2","v2.3.2rc1","v2.3.2rc2","v2.3.2rc3","v2.3.2rc4","v2.3.2rc5","v2.3.3","v2.4.0","v2.4.0rc1","v2.4.0rc2","v2.4.0rc3","v2.4.0rc4","v2.4.0rc5","v2.4.1","v2.4.1rc1","v2.4.1rc2","v2.4.1rc3","v2.4.1rc4","v2.4.2","v2.4.2rc1","v2.4.2rc2","v2.4.2rc3","v2.4.3","v2.4.3rc1","v2.4.3rc2","v2.4.3rc3","v2.4.4","v2.4.5","v2.5.0","v2.5.0rc1","v2.5.0rc2","v2.5.1","v2.5.2","v2.6.0","v2.6.0rc1","v2.6.0rc2","v2.6.0rc3","v2.6.0rc4","v2.6.1","v2.6.2","v2.6.3","v2.6.4","v2.6.5","v2.7.0","v2.7.0rc1","v2.7.0rc2","v2.7.0rc3","v2.7.1","v2.7.2","v2.7.3","v2.7.4","v2.8.0","v2.8.0rc1","v2.8.0rc2","v2.8.0rc3","v2.8.1","v2.8.2","v2.8.3","v2.8.4","v2.9.0","v2.9.0rc1","v2.9.0rc2","v2.9.1","v2.9.2","v2.9.3","v2.9.4","v3.0.0","v3.0.0rc1","v3.0.0rc2","v3.0.0rc3","v3.0.1","v3.0.2","v3.1.0","v3.1.0rc1","v3.1.0rc2","v3.1.1","v3.1.2","v3.1.3","v3.1.4","v3.1.5","v3.2.0","v3.2.0rc1","v3.2.0rc2","v3.2.1","v3.2.2","v3.3.0","v3.3.0rc1","v3.3.0rc2","v3.3.0rc3","v3.3.1","v3.3.2","v3.3.3","v3.4.0","v3.4.0rc1","v3.4.0rc2","v3.4.1","v3.4.10","v3.4.2","v3.4.3","v3.4.4","v3.4.5","v3.4.6","v3.4.7","v3.4.8","v3.4.9","v3.5.0","v3.5.0rc1","v3.5.0rc2","v3.5.0rc3","v3.5.1","v3.5.10","v3.5.11","v3.5.12","v3.5.13","v3.5.2","v3.5.3","v3.5.4","v3.5.5","v3.5.6","v3.5.7","v3.5.8","v3.5.9","v4.0.0","v4.0.0rc1","v4.0.0rc2","v4.0.0rc3","v4.0.0rc4","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.0rc1","v4.1.0rc2","v4.1.0rc3","v4.1.1","v4.1.2","v4.1.3","v4.1.4","v4.1.5","v4.1.6","v4.1.7","v4.2.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42451.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}