Mastodon
mastodon.socialAn open-source, distributed social media platform functioning similarly to Twitter, without algorithmic timeline manipulations. It operates across independent servers.
- Homepage: mastodon.social
- GitHub: github.com/mastodon/mastodon
- Privacy: mastodon.social/privacy-policy
- Web info: web-check.xyz/check/mastodon.social
Mastodon Privacy Policy
Privacy Policy Summary
- The user is informed about security practices
- The service can delete your account without prior notice
- This service is only available to users of a certain age
- The service provides two factor authentification for your account
- User logs are deleted after a finite period of time
- You have the right to leave this service at any time
- There is a date of the last update of the agreements
- Your personal data is not sold
- The service allows you to use pseudonyms
- Private messages can be read
- This service collects your IP address, which can be used to view your approximate location
- The posting of untagged pornographic content is prohibited
- This service offers a symbolic but nonbinding statement about a matter of opinion, ethics, society, or politics
- You shall not interfere with another person's enjoyment of the service
- You agree not to submit libelous, harassing or threatening content
- Terms may be changed any time at their discretion, without notice to you
- Details are provided about what kind of information they collect
- This service gives your personal data to third parties involved in its operation
- The publishing of personally identifiable information without the ownerβs consent is not allowed
- The service is open-source
- You are prohibited from sending chain letters, junk mail, spam or any unsolicited messages
- This service reserves the right to disclose your personal information without notifying you
Score
Documents
- Code of ConductCreated 07 Aug 18, Last modified 5 years ago
- Privacy PolicyCreated 07 Aug 18, Last modified 3 months ago
- Terms of ServiceCreated 09 Nov 19, Last modified 1 year ago
Domains Covered by Policy
- mastodon.social
- joinmastodon.org
- mastodon.online
- mastodon.cloud
About the Data
This data is kindly provided by tosdr.org. Read full report at: #639
Mastodon Source Code
Author
Description
Your self-hosted, globally interconnected microblogging community
Homepage
https://joinmastodon.orgLicense
AGPL-3.0
Created
22 Feb 16
Last Updated
29 Jul 26
Latest version
Primary Language
Ruby
Size
396,824 KB
Stars
50,147
Forks
7,480
Watchers
50,147
Language Usage
Star History
Top Contributors
-
@Gargron (4246)
-
@ClearlyClaire (2845)
-
@mjankowski (2180)
-
@dependabot[bot] (2147)
-
@renovate[bot] (1996)
-
@dependabot-preview[bot] (720)
-
@github-actions[bot] (642)
-
@ykzts (549)
-
@diondiondion (412)
-
@ChaosExAnima (318)
-
@renchap (270)
-
@nschonni (249)
-
@akihikodaki (239)
-
@oneiros (203)
-
@mkljczk (156)
-
@unarist (140)
-
@tribela (139)
-
@ThisIsMissEm (123)
-
@noellabo (119)
-
@shleeable (116)
-
@abcang (106)
-
@yiskah (103)
-
@mayaeh (99)
-
@nolanlawson (94)
-
@ysksn (88)
-
@sorin-davidoi (81)
-
@danielmbrasil (79)
-
@c960657 (75)
-
@vmstan (69)
-
@zunda (54)
-
@renatolond (47)
-
@lynlynlynx (46)
-
@takayamaki (43)
-
@ineffyble (42)
-
@alpaca-tc (41)
-
@nclm (37)
-
@trwnh (35)
-
@ariasuni (33)
-
@blackle (31)
-
@brawaru (30)
-
@JantsoP (30)
-
@Quent-in (30)
-
@nullkal (27)
-
@yookoala (26)
-
@dunn (26)
-
@Aditoo17 (24)
-
@Quenty31 (24)
-
@shuheiktgw (23)
-
@ashfurrow (22)
-
@gunchleoc (21)
-
@danhunsaker (20)
-
@eramdam (19)
-
@masarakki (18)
-
@hinaloe (17)
-
@ticky (17)
-
@nightpool (16)
-
@matteoaquila (16)
-
@Wonderfall (16)
-
@stephenburgess8 (16)
-
@hcmiya (16)
-
@larouxn (16)
-
@mgmn (15)
-
@MitarashiDango (15)
-
@marek-lach (15)
-
@rinsuki (15)
-
@arte7 (15)
-
@rkarabut (15)
-
@marrus-sh (14)
-
@krainboltgreene (14)
-
@Artoria2e5 (14)
-
@deepy (13)
-
@pfigel (13)
-
@MaciekBaron (12)
-
@Sylvhem (12)
-
@koyuawsmbrtn (12)
-
@dracos (12)
-
@angristan (12)
-
@MasterGroosha (12)
-
@clworld (12)
-
@Aldarone (12)
-
@BenLubar (11)
-
@mashirozx (11)
-
@JeanGauthier (11)
-
@kschaper (11)
-
@alixrossi (11)
-
@beatrix-bitrot (11)
-
@evanminto (10)
-
@ShadowJonathan (10)
-
@MightyPork (10)
-
@ashleyhull-versent (10)
-
@kedamaDQ (10)
-
@adbelle (10)
-
@yhirano55 (10)
-
@lindwurm (9)
-
@mistydemeo (9)
-
@jsgoldstein (9)
-
@mfmfuyu (9)
-
@aschmitz (9)
-
@timothyjrogers (9)
-
@TheEssem (9)
Recent Commits
-
renovate[bot] (29 Jul 26)
Update dependency sass to v1.102.0 (#39972) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
Echo (29 Jul 26)
Adds useMergedRefs and useListFocus hooks (#39975)
-
Shlee (29 Jul 26)
Fix attachment_batch to correctly resets retries for S3 storage loops. (#39979)
-
Shlee (29 Jul 26)
Fix typo in process_status_update_service.rb allowing more than 4 media attachments (#39978)
-
github-actions[bot] (29 Jul 26)
New Crowdin Translations (automated) (#39985) Co-authored-by: GitHub Actions <[email protected]>
-
Shlee (29 Jul 26)
Fix typo in button components redesign.tsx (#39981)
-
Shlee (29 Jul 26)
Fix missing AccountWarning from merging.rb (#39982)
-
Echo (28 Jul 26)
Redesign composer thunks (#39945)
-
Echo (28 Jul 26)
Redesign components: Radio buttons (#39943)
-
David Roetzel (28 Jul 26)
Add another permission check to admin area (#39974)
-
Sharlayan (28 Jul 26)
Fix oversized profile image crop uploads (#39958)
-
Claire (28 Jul 26)
Add documentation for new signature schemes to FEDERATION.md (#39735)
-
Claire (28 Jul 26)
Fix remote users not being re-followed after URI change (#39861)
-
renovate[bot] (28 Jul 26)
Update dependency @unhead/react to v3.2.3 (#39883) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update dependency @vitejs/plugin-react to v6.0.4 (#39925) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update dependency @vitejs/plugin-legacy to v8.2.2 (#39938) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
github-actions[bot] (28 Jul 26)
New Crowdin Translations (automated) (#39971) Co-authored-by: GitHub Actions <[email protected]>
-
Echo (28 Jul 26)
Cancel emoji search requests (#39947)
-
Claire (28 Jul 26)
Remove processing of collections of activities (#39932)
-
renovate[bot] (28 Jul 26)
Update dependency simplecov to v1.0.3 (#39962) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update dependency csv to v3.3.6 (#39961) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update dependency react-easy-crop to v6.2.3 (#39955) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update react monorepo to v19.2.8 (#39950) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
renovate[bot] (28 Jul 26)
Update dependency sass to v1.102.0 (#39910) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
Claire (28 Jul 26)
Add uniqueness constraint on Account `uri` (#39882)
-
Claire (28 Jul 26)
Remove support for `Reject` and `Accept` of `QuoteRequest` that cannot be found by `id` (#39833)
-
David Roetzel (27 Jul 26)
Improve enforcement of collection item limit (#39969)
-
Claire (27 Jul 26)
Merge commit from fork * Fix GHSA-7jvv-fhmg-wpfw * Fix GHSA-hx34-2pfw-2qfj * Fix GHSA-vwhj-3g83-v276 * Bump version to v4.6.4
-
Claire (27 Jul 26)
Fix being unable to vote in polls without an expiration date (#39949)
-
github-actions[bot] (27 Jul 26)
New Crowdin Translations (automated) (#39954) Co-authored-by: GitHub Actions <[email protected]>
Mastodon Security
Security Advisories (51)
- high Patched CVSS 7.4
CVE-2026-59825 Unwanted deactivation of SSL/TLS certificate verification
- high Patched CVSS 7.5
CVE-2026-50129 DoS via unhandled NoMethodError in MATH_TRANSFORMER
- medium Patched CVSS 5.3
CVE-2026-50128 Spoofing of attribution domains
- high Patched CVSS 7.5
CVE-2026-47777 Consent-check bypass in remote Collections
- high Patched CVSS 8.6
CVE-2026-47389 SSRF protection bypass on older Ruby versions (incomplete remediation for GHSA-xfrj-c749-jxxq)
- high Patched
CVE-2026-46348 SSRF Bypass via IPv6 Unspecified Address (::)
- medium Patched CVSS 5.3
CVE-2026-46349 LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- high Patched
CVE-2026-41259 Insufficient verification of email addresses
- medium Patched CVSS 4.8
CVE-2026-33869 Denial of service for quote authorization
- medium Patched CVSS 4.3
CVE-2026-33868 GET-Based Open Redirect via '/web/%2F<domain>'
- high Patched
CVE-2026-27468 Allowing unconfirmed FASP to make subscriptions
- low Patched
GHSA-46w6-g98f-wxqm SSRF via unvalidated FASP Provider base_url
- medium Patched CVSS 6.5
CVE-2026-25540 Signature-dependent ActivityPub collection responses cached under signature-independent keys
- medium Patched CVSS 5.3
CVE-2026-23961 Remote suspension bypass
- medium Patched CVSS 6.5
CVE-2026-23964 Insufficient access control to push notification settings
- high Patched CVSS 7.5
CVE-2026-23962 Denial of Service from a single post (client/server)
- high Patched
CVE-2026-22245 SSRF Protection bypass
- medium Patched CVSS 6.5
CVE-2026-22246 Local users can enumerate and access severed relationships of every other local user
- low Patched CVSS 3.7
CVE-2025-67500 Inconsistent error handling allows anonymously checking existence of known private posts
- medium Patched CVSS 4.3
CVE-2025-62605 Quotes control bypass
- medium Patched CVSS 4.3
CVE-2025-62176 Streaming server allows OAuth clients without the `read` scope to subscribe to public channels
- low Patched CVSS 3.5
CVE-2025-62174 Changing a user's password via CLI does not revoke sessions & access tokens
- medium Patched CVSS 4.3
CVE-2025-62175 Disabled and suspended user accounts stay connected to the streaming API and can connect afterwards
- medium Patched CVSS 5.3
CVE-2025-54879 Mastodon confirmation eβmail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
- low Patched
GHSA-x2rc-v5wx-g3m5 Lack of sanitization of user-facing URLs for remote objects can lead to XSS in misconfigured servers
- medium Patched CVSS 5.3
CVE-2025-27157 Missing rate-limit on sign-up email verification
- medium Patched CVSS 5.3
CVE-2025-27399 Domain blocks & rationales ignore user approval when visibility set as "users"
- low Patched
GHSA-mq2m-hr29-8gqf OEmbed embeds allow <embed> tag (blocked by CSP)
- medium Patched CVSS 4.3
CVE-2026-23963 Missing length limits on list names, filter names, and filter keywords
- medium Patched CVSS 5.3
GHSA-5wxh-3p65-r4g6 Partial Denial of Service due to insufficient validation of remote actors
- medium Patched CVSS 5.3
GHSA-3m9q-ww7w-qc5j Subdomains allow spoofing of accounts in search results
- high Patched CVSS 7.5
GHSA-jpxp-r43f-rhvx Potential Polynomial regular expression used on uncontrolled data
- medium Patched CVSS 5.3
GHSA-58x8-3qxw-6hm7 Insufficient permission checking on multiple API endpoints
- high Patched CVSS 8.2
CVE-2024-37903 Improper authorship check on audience extension for existing posts
- low Patched CVSS 2.6
GHSA-vp5r-5pgw-jwqx Streaming continues to send events for a user after access token is revoked
- low Patched
GHSA-5fq7-3p3j-9vrf Private mention filtering can be bypassed
- medium Patched CVSS 5.9
GHSA-q3rg-xx5v-4mxh Missing rate-limit to password change endpoint
- medium Patched CVSS 6.5
CVE-2026-48028 Removal of integrity-protected JSON entries from signed activities
- medium Patched CVSS 4.8
CVE-2023-49952 Bypassing rate limiting with X-Forwarded-For header
- high Patched CVSS 8.5
CVE-2024-25623 Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
- critical Patched CVSS 9.4
CVE-2024-23832 Remote user impersonation and takeover
- low Patched CVSS 3.1
CVE-2024-25619 Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed
- medium Patched
CVE-2024-25618 External OpenID Connect Account Takeover by E-Mail Change
- high Patched CVSS 8.3
CVE-2023-42452 Stored XSS through the translation feature
- medium Patched CVSS 5.4
CVE-2023-42450 Server-side request forgery
- high Patched CVSS 7.7
CVE-2023-42451 Invalid domain name normalization
- medium Patched CVSS 5.4
CVE-2023-36462 Verified profile links can be formatted in a misleading way
- high Patched CVSS 7.5
CVE-2023-36461 Denial of Service through slow HTTP responses
- critical Patched CVSS 9.9
CVE-2023-36460 Arbitrary file creation through media attachments
- critical Patched CVSS 9.3
CVE-2023-36459 XSS through oEmbed preview cards
- high Patched CVSS 7.7
CVE-2023-28853 Blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
Mastodon Website
Website
Mastodon
The original server of Mastodon, operated by Mastodon GmbH for the common good.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address 151.101.1.55
- Location San Francisco, California, United States of America, NA
- ISP Fastly Inc.
- ASN AS54113
Associated Countries
-
US
Safety Score
Website marked as safe
100%
Blacklist Check
mastodon.social was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Mastodon Docker
Mastodon Reviews
More Social Networks
-
A fully open-source, self-hostable discussion platform usable as a mailing list, discussion forum, or long-form chat room.
-
A federated, open-source link aggregator and discussion platform, similar to Reddit. Built on ActivityPub. Wide range of cross-platform client apps.
-
nostr stands for Notes and other stuff transmitted by relays. It is an open protocol, not merely a platform. This distinction enables truly censorship-resistant and global value-for-value publishing on the web. With the power to replace data-greedy applications like Twitter and Instagram, nostr offers a promising alternative for users seeking a more private and secure online experience without algorithmic manipulations. ".... I feel like Iβm looking at the future." that is what Snowden wrote about nostr.
About the Data: Mastodon
API
You can access Mastodon's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/mastodon The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Mastodon
Help your friends compare Social Networks, and pick
privacy-respecting software and services.
Share Mastodon and Awesome Privacy with your network!