CVE-2026-25540 | Mastodon up to 4.3.18/4.4.12/4.5.5 ActivityPub Endpoint Rails.cache cache containing sensitive information (GHSA-ccpr-m53r-mfwr / EUVD-2026-5329)
A vulnerability was found in Mastodon up to 4.3.18/4.4.12/4.5.5 and classified as critical. Affected by this vulnerability is the function Rails.cache of the component ActivityPub Endpoint. Such manipulation leads to use of cache containing sensitive information.
This vulnerability is uniquely identified as CVE-2026-25540. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.