Mastodon
mastodon.socialAn open-source, distributed social media platform functioning similarly to Twitter, without algorithmic timeline manipulations. It operates across independent servers.
- Homepage:mastodon.social
- GitHub:github.com/mastodon/mastodon
- Privacy:mastodon.social/privacy-policy
- Web info:web-check.xyz/check/mastodon.social
Mastodon Privacy Policy
Privacy Policy Summary
- The user is informed about security practices
- The service can delete your account without prior notice
- This service is only available to users of a certain age
- The service provides two factor authentification for your account
- User logs are deleted after a finite period of time
- You have the right to leave this service at any time
- There is a date of the last update of the agreements
- Your personal data is not sold
- The service allows you to use pseudonyms
- Private messages can be read
- This service collects your IP address, which can be used to view your approximate location
- The posting of untagged pornographic content is prohibited
- This service offers a symbolic but nonbinding statement about a matter of opinion, ethics, society, or politics
- You shall not interfere with another person's enjoyment of the service
- You agree not to submit libelous, harassing or threatening content
- Terms may be changed any time at their discretion, without notice to you
- Details are provided about what kind of information they collect
- This service gives your personal data to third parties involved in its operation
- The publishing of personally identifiable information without the owner’s consent is not allowed
- The service is open-source
- You are prohibited from sending chain letters, junk mail, spam or any unsolicited messages
- This service reserves the right to disclose your personal information without notifying you
Score
Documents
- Code of ConductCreated 07 Aug 18, Last modified 5 years ago
- Privacy PolicyCreated 07 Aug 18, Last modified 5 months ago
- Terms of ServiceCreated 09 Nov 19, Last modified 1 year ago
Domains Covered by Policy
- mastodon.social
- joinmastodon.org
- mastodon.online
- mastodon.cloud
About the Data
This data is kindly provided by tosdr.org. Read full report at: #639
Mastodon Source Code
Author
Description
Your self-hosted, globally interconnected microblogging community
Homepage
https://joinmastodon.orgRepository
- LicenseAGPL-3.0
- Created22 Feb 16
- Primary languageRuby
- Size399,678 KB
- Stars50,264
- Forks7,487
- Watchers50,264
Top Contributors
@Gargron (4252)
@ClearlyClaire (2884)
@mjankowski (2188)
@dependabot[bot] (2147)
@renovate[bot] (2048)
@dependabot-preview[bot] (720)
@github-actions[bot] (666)
@ykzts (549)
@diondiondion (452)
@ChaosExAnima (359)
@renchap (274)
@nschonni (249)
@akihikodaki (239)
@oneiros (203)
@mkljczk (156)
@unarist (140)
@tribela (140)
@shleeable (131)
@ThisIsMissEm (123)
@noellabo (119)
@abcang (106)
@yiskah (103)
@mayaeh (99)
@nolanlawson (94)
@ysksn (88)
@sorin-davidoi (81)
@danielmbrasil (79)
@c960657 (75)
@vmstan (69)
@zunda (54)
@renatolond (47)
@lynlynlynx (46)
@takayamaki (43)
@ineffyble (42)
@alpaca-tc (41)
@nclm (37)
@trwnh (35)
@ariasuni (33)
@blackle (31)
@Quent-in (30)
@brawaru (30)
@JantsoP (30)
@nullkal (27)
@yookoala (26)
@dunn (26)
@Aditoo17 (24)
@Quenty31 (24)
@shuheiktgw (23)
@ashfurrow (22)
@gunchleoc (21)
@danhunsaker (20)
@eramdam (19)
@masarakki (18)
@hinaloe (17)
@ticky (17)
@hcmiya (16)
@larouxn (16)
@stephenburgess8 (16)
@Wonderfall (16)
@matteoaquila (16)
@nightpool (16)
@mgmn (15)
@MitarashiDango (15)
@marek-lach (15)
@rinsuki (15)
@rkarabut (15)
@arte7 (15)
@krainboltgreene (14)
@marrus-sh (14)
@Artoria2e5 (14)
@pfigel (13)
@deepy (13)
@angristan (12)
@koyuawsmbrtn (12)
@Sylvhem (12)
@MaciekBaron (12)
@dracos (12)
@MasterGroosha (12)
@clworld (12)
@Aldarone (12)
@BenLubar (11)
@mashirozx (11)
@alixrossi (11)
@beatrix-bitrot (11)
@kschaper (11)
@JeanGauthier (11)
@yhirano55 (10)
@kedamaDQ (10)
@ashleyhull-versent (10)
@MightyPork (10)
@ShadowJonathan (10)
@evanminto (10)
@TheEssem (10)
@adbelle (10)
@mistydemeo (9)
@lindwurm (9)
@devkral (9)
@camponez (9)
@timothyjrogers (9)
@aschmitz (9)
Recent Commits
diondiondion(03 Sept 26)
Add link to homepage to 404 error page (#40369)
diondiondion(03 Sept 26)
Redesign: Update column headers on Custom Feed pages & Followed Hashtags overview page (#40376)
diondiondion(03 Sept 26)
Redesign: Add "New" button to Messages column header (#40377)
Echo(03 Sept 26)
Hotkeys, Storybook theme fix, allow bullets (#40375)
diondiondion(03 Sept 26)
Redesign: Add new column header to post/thread page (#40372)
Echo(03 Sept 26)
Use new PolymorphicProps to silence error around missing ref (#40371)
diondiondion(03 Sept 26)
Redesign: Update notifications column header (#40370)
Echo(03 Sept 26)
Composer redesign: Quotes (#40364) Co-authored-by: diondiondion <[email protected]>
diondiondion(02 Sept 26)
Redesign: Update column header on many pages (#40362)
Claire(02 Sept 26)
Remove `ignored_columns` for 4.3 and earlier (#40359)
github-actions[bot](02 Sept 26)
New Crowdin Translations (automated) (#40353) Co-authored-by: GitHub Actions <[email protected]>
Claire(02 Sept 26)
Add `reference` to `MastodonLocationState` (#40356)
diondiondion(02 Sept 26)
Redesign: Fix mobile navigation background colour (#40354)
diondiondion(02 Sept 26)
Refactor `color-bg-blend` token (#40350)
Echo(01 Sept 26)
Composer redesign: Make the composer cover the viewport (#40349)
diondiondion(01 Sept 26)
Redesign: Update global CSS size variables (#40348)
diondiondion(01 Sept 26)
Refactor Messages/Private Mentions page to TS (#40347)
Echo(01 Sept 26)
Composer redesign: Mobile updates (#40346)
diondiondion(01 Sept 26)
Redesign: Add new column header to "Saved Posts" and "Post Likes" pages (#40345)
Claire(28 Aug 26)
Bump version to v4.7.1
Claire(27 Aug 26)
Fix GHSA-vx32-x96w-qq65
Juan Hernández Babón(26 Aug 26)
Fixes GHSA-62j4-hvj7-px3f
Claire(26 Aug 26)
Fix GHSA-vgm8-frgh-rh2v
github-actions[bot](01 Sept 26)
New Crowdin Translations (automated) (#40342) Co-authored-by: GitHub Actions <[email protected]>
Eugen Rochko(31 Aug 26)
Add even more features to feature usage counter (#40340)
diondiondion(31 Aug 26)
Add new `ColumnHeader` component (#40339)
diondiondion(31 Aug 26)
Redesign: Update main layout background colors (#40333)
Claire(31 Aug 26)
Fix invited-without-approval-bypass not being asked for a textual reason (#40332)
github-actions[bot](31 Aug 26)
New Crowdin Translations (automated) (#40326) Co-authored-by: GitHub Actions <[email protected]>
Echo(31 Aug 26)
Fixes bug with border token name (#40331)
Mastodon Security
Security Advisories (56)
- highPatchedCVSS 7.2
GHSA-62j4-hvj7-px3fDisabling a staff account does not remove its access to the admin API
- highPatchedCVSS 7.4
GHSA-vx32-x96w-qq65Accounts provisioned by LDAP or SSO with two-factor enabled can be signed in to with any password
- mediumPatched
CVE-2026-72916SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- highPatchedCVSS 7.5
CVE-2026-72915Personally-identifying information disclosure due to incorrect access control validation
- highPatchedCVSS 7.5
CVE-2026-72914Denial of Service through insufficient authentification of statistics endpoints
- highPatchedCVSS 7.4
CVE-2026-59825Unwanted deactivation of SSL/TLS certificate verification
- highPatchedCVSS 7.5
CVE-2026-50129DoS via unhandled NoMethodError in MATH_TRANSFORMER
- mediumPatchedCVSS 5.3
CVE-2026-50128Spoofing of attribution domains
- highPatchedCVSS 7.5
CVE-2026-47777Consent-check bypass in remote Collections
- highPatchedCVSS 8.6
CVE-2026-47389SSRF protection bypass on older Ruby versions (incomplete remediation for GHSA-xfrj-c749-jxxq)
- highPatched
CVE-2026-46348SSRF Bypass via IPv6 Unspecified Address (::)
- mediumPatchedCVSS 5.3
CVE-2026-46349LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- highPatched
CVE-2026-41259Insufficient verification of email addresses
- mediumPatchedCVSS 4.8
CVE-2026-33869Denial of service for quote authorization
- mediumPatchedCVSS 4.3
CVE-2026-33868GET-Based Open Redirect via '/web/%2F<domain>'
- highPatched
CVE-2026-27468Allowing unconfirmed FASP to make subscriptions
- lowPatched
GHSA-46w6-g98f-wxqmSSRF via unvalidated FASP Provider base_url
- mediumPatchedCVSS 6.5
CVE-2026-25540Signature-dependent ActivityPub collection responses cached under signature-independent keys
- mediumPatchedCVSS 5.3
CVE-2026-23961Remote suspension bypass
- mediumPatchedCVSS 6.5
CVE-2026-23964Insufficient access control to push notification settings
- highPatchedCVSS 7.5
CVE-2026-23962Denial of Service from a single post (client/server)
- highPatched
CVE-2026-22245SSRF Protection bypass
- mediumPatchedCVSS 6.5
CVE-2026-22246Local users can enumerate and access severed relationships of every other local user
- lowPatchedCVSS 3.7
CVE-2025-67500Inconsistent error handling allows anonymously checking existence of known private posts
- mediumPatchedCVSS 4.3
CVE-2025-62605Quotes control bypass
- mediumPatchedCVSS 4.3
CVE-2025-62176Streaming server allows OAuth clients without the `read` scope to subscribe to public channels
- lowPatchedCVSS 3.5
CVE-2025-62174Changing a user's password via CLI does not revoke sessions & access tokens
- mediumPatchedCVSS 4.3
CVE-2025-62175Disabled and suspended user accounts stay connected to the streaming API and can connect afterwards
- mediumPatchedCVSS 5.3
CVE-2025-54879Mastodon confirmation e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
- lowPatched
GHSA-x2rc-v5wx-g3m5Lack of sanitization of user-facing URLs for remote objects can lead to XSS in misconfigured servers
- mediumPatchedCVSS 5.3
CVE-2025-27157Missing rate-limit on sign-up email verification
- mediumPatchedCVSS 5.3
CVE-2025-27399Domain blocks & rationales ignore user approval when visibility set as "users"
- lowPatched
GHSA-mq2m-hr29-8gqfOEmbed embeds allow <embed> tag (blocked by CSP)
- mediumPatchedCVSS 4.3
CVE-2026-23963Missing length limits on list names, filter names, and filter keywords
- mediumPatchedCVSS 5.3
GHSA-5wxh-3p65-r4g6Partial Denial of Service due to insufficient validation of remote actors
- mediumPatchedCVSS 5.3
GHSA-3m9q-ww7w-qc5jSubdomains allow spoofing of accounts in search results
- highPatchedCVSS 7.5
GHSA-jpxp-r43f-rhvxPotential Polynomial regular expression used on uncontrolled data
- mediumPatchedCVSS 5.3
GHSA-58x8-3qxw-6hm7Insufficient permission checking on multiple API endpoints
- highPatchedCVSS 8.2
CVE-2024-37903Improper authorship check on audience extension for existing posts
- lowPatchedCVSS 2.6
GHSA-vp5r-5pgw-jwqxStreaming continues to send events for a user after access token is revoked
- lowPatched
GHSA-5fq7-3p3j-9vrfPrivate mention filtering can be bypassed
- mediumPatchedCVSS 5.9
GHSA-q3rg-xx5v-4mxhMissing rate-limit to password change endpoint
- mediumPatchedCVSS 6.5
CVE-2026-48028Removal of integrity-protected JSON entries from signed activities
- mediumPatchedCVSS 4.8
CVE-2023-49952Bypassing rate limiting with X-Forwarded-For header
- highPatchedCVSS 8.5
CVE-2024-25623Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
- criticalPatchedCVSS 9.4
CVE-2024-23832Remote user impersonation and takeover
- lowPatchedCVSS 3.1
CVE-2024-25619Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed
- mediumPatched
CVE-2024-25618External OpenID Connect Account Takeover by E-Mail Change
- highPatchedCVSS 8.3
CVE-2023-42452Stored XSS through the translation feature
- mediumPatchedCVSS 5.4
CVE-2023-42450Server-side request forgery
- highPatchedCVSS 7.7
CVE-2023-42451Invalid domain name normalization
- mediumPatchedCVSS 5.4
CVE-2023-36462Verified profile links can be formatted in a misleading way
- highPatchedCVSS 7.5
CVE-2023-36461Denial of Service through slow HTTP responses
- criticalPatchedCVSS 9.9
CVE-2023-36460Arbitrary file creation through media attachments
- criticalPatchedCVSS 9.3
CVE-2023-36459XSS through oEmbed preview cards
- highPatchedCVSS 7.7
CVE-2023-28853Blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
Mastodon Website
Website
Mastodon
The original server of Mastodon, operated by Mastodon GmbH for the common good.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address151.101.193.55
- LocationSan Francisco,California,United States of America,NA
- ISPFastly Inc.
- ASNAS54113
Associated Countries
US
Safety Score
Website marked as safe
100%
Blacklist Check
mastodon.social was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Mastodon Docker
Container Info
Mastodon
[Mastodon](https://github.com/mastodon/mastodon/) is a free, open-source social network server based on ActivityPub where users can follow friends and discover new ones..
View on DockerHub
linuxserver/mastodon:latestRun Command
docker run -d \
-p 80:80/tcp \
-p 443:443/tcp \
-p 9394:9394/tcp \
-e PUID=${PUID} \
-e PGID=${PGID} \
-e TZ=${TZ} \
-e LOCAL_DOMAIN=${LOCAL_DOMAIN} \
-e REDIS_HOST=${REDIS_HOST} \
-e REDIS_PORT=${REDIS_PORT} \
-e DB_HOST=${DB_HOST} \
-e DB_USER=${DB_USER} \
-e DB_NAME=${DB_NAME} \
-e DB_PASS=${DB_PASS} \
-e DB_PORT=${DB_PORT} \
-e ES_ENABLED=${ES_ENABLED} \
-e ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY=${ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY} \
-e ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY=${ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY} \
-e ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT=${ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT} \
-e SECRET_KEY_BASE=${SECRET_KEY_BASE} \
-e OTP_SECRET=${OTP_SECRET} \
-e VAPID_PRIVATE_KEY=${VAPID_PRIVATE_KEY} \
-e VAPID_PUBLIC_KEY=${VAPID_PUBLIC_KEY} \
-e SMTP_SERVER=${SMTP_SERVER} \
-e SMTP_PORT=${SMTP_PORT} \
-e SMTP_LOGIN=${SMTP_LOGIN} \
-e SMTP_PASSWORD=${SMTP_PASSWORD} \
-e SMTP_FROM_ADDRESS=${SMTP_FROM_ADDRESS} \
-e S3_ENABLED=${S3_ENABLED} \
-e WEB_DOMAIN=${WEB_DOMAIN} \
-e ES_HOST=${ES_HOST} \
-e ES_PORT=${ES_PORT} \
-e ES_USER=${ES_USER} \
-e ES_PASS=${ES_PASS} \
-e S3_BUCKET=${S3_BUCKET} \
-e AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} \
-e AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} \
-e S3_ALIAS_HOST=${S3_ALIAS_HOST} \
-e SIDEKIQ_ONLY=${SIDEKIQ_ONLY} \
-e SIDEKIQ_QUEUE=${SIDEKIQ_QUEUE} \
-e SIDEKIQ_DEFAULT=${SIDEKIQ_DEFAULT} \
-e SIDEKIQ_THREADS=${SIDEKIQ_THREADS} \
-e DB_POOL=${DB_POOL} \
-e NO_CHOWN=${NO_CHOWN} \
-e MASTODON_PROMETHEUS_EXPORTER_ENABLED=${MASTODON_PROMETHEUS_EXPORTER_ENABLED} \
-v /srv/lsio/mastodon/config:/config \
--restart=unless-stopped \
linuxserver/mastodon:latestCompose File
version: 3.8
services:
mastodon-container:
image: "linuxserver/mastodon:latest"
ports:
- "80:80/tcp"
- "443:443/tcp"
- "9394:9394/tcp"
environment:
PUID: 1000
PGID: 1000
TZ: Etc/UTC
LOCAL_DOMAIN: example.com
REDIS_HOST: redis
REDIS_PORT: 6379
DB_HOST: db
DB_USER: mastodon
DB_NAME: mastodon
DB_PASS: mastodon
DB_PORT: 5432
ES_ENABLED: false
ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY:
ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY:
ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT:
SECRET_KEY_BASE:
OTP_SECRET:
VAPID_PRIVATE_KEY:
VAPID_PUBLIC_KEY:
SMTP_SERVER: mail.example.com
SMTP_PORT: 25
SMTP_LOGIN:
SMTP_PASSWORD:
SMTP_FROM_ADDRESS: [email protected]
S3_ENABLED: false
WEB_DOMAIN: mastodon.example.com
ES_HOST: es
ES_PORT: 9200
ES_USER: elastic
ES_PASS: elastic
S3_BUCKET:
AWS_ACCESS_KEY_ID:
AWS_SECRET_ACCESS_KEY:
S3_ALIAS_HOST:
SIDEKIQ_ONLY: false
SIDEKIQ_QUEUE:
SIDEKIQ_DEFAULT: false
SIDEKIQ_THREADS: 5
DB_POOL: 5
NO_CHOWN:
MASTODON_PROMETHEUS_EXPORTER_ENABLED:
volumes:
- "/srv/lsio/mastodon/config:/config"
restart: unless-stoppedEnvironment Variables
- Var NameDefault
- PUID1000
- PGID1000
- TZEtc/UTC
- LOCAL_DOMAINexample.com
- REDIS_HOSTredis
- REDIS_PORT6379
- DB_HOSTdb
- DB_USERmastodon
- DB_NAMEmastodon
- DB_PASSmastodon
- DB_PORT5432
- ES_ENABLEDfalse
- ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEYnull
- ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEYnull
- ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALTnull
- SECRET_KEY_BASEnull
- OTP_SECRETnull
- VAPID_PRIVATE_KEYnull
- VAPID_PUBLIC_KEYnull
- SMTP_SERVERmail.example.com
- SMTP_PORT25
- SMTP_LOGINnull
- SMTP_PASSWORDnull
- SMTP_FROM_ADDRESS[email protected]
- S3_ENABLEDfalse
- WEB_DOMAINmastodon.example.com
- ES_HOSTes
- ES_PORT9200
- ES_USERelastic
- ES_PASSelastic
- S3_BUCKETnull
- AWS_ACCESS_KEY_IDnull
- AWS_SECRET_ACCESS_KEYnull
- S3_ALIAS_HOSTnull
- SIDEKIQ_ONLYfalse
- SIDEKIQ_QUEUEnull
- SIDEKIQ_DEFAULTfalse
- SIDEKIQ_THREADS5
- DB_POOL5
- NO_CHOWNnull
- MASTODON_PROMETHEUS_EXPORTER_ENABLEDnull
Port List
- 80:80/tcp
- 443:443/tcp
- 9394:9394/tcp
Volume Mounting
- Container PathHost Bind
- /config/srv/lsio/mastodon/config
Mastodon Reviews
More Social Networks
A fully open-source, self-hostable discussion platform usable as a mailing list, discussion forum, or long-form chat room.
A federated, open-source link aggregator and discussion platform, similar to Reddit. Built on ActivityPub. Wide range of cross-platform client apps.
nostr stands for Notes and other stuff transmitted by relays. It is an open protocol, not merely a platform. This distinction enables truly censorship-resistant and global value-for-value publishing on the web. With the power to replace data-greedy applications like Twitter and Instagram, nostr offers a promising alternative for users seeking a more private and secure online experience without algorithmic manipulations. ".... I feel like I’m looking at the future." that is what Snowden wrote about nostr.
About the Data: Mastodon
Edit Mastodon Data
You can edit Mastodon's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access Mastodon's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/mastodonThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Mastodon
Help your friends compare Social Networks, and pick privacy-respecting software and services.
Share Mastodon and Awesome Privacy with your network!