Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Mastodon’s maintainers have published security fixes and urged server administrators to install them, but that does not certify every Mastodon server as safe. Each instance is independently operated, so its software maintenance, rules, moderation and privacy practices matter. The headline’s claim of “4 bugs” is not confirmed by the official sources cited here: Mastodon’s v4.6.7 notes list three security-fix items, and the September 2026 update identifies several releases containing security fixes without attributing an exact four-issue count to them.

What Mastodon patched—and what the “4 bugs” claim establishes

Mastodon is not one centrally operated service. It is software that administrators run on separate servers, or instances, which connect across the fediverse. The Mastodon project’s September 15, 2026 engineering update listed versions 4.7.1, 4.6.7, 4.5.17 and 4.4.24 as supported releases at that time and said they contained security fixes. It advised administrators to update. Mastodon’s September 2026 engineering update

The official material available for this article does not verify that exactly four bugs were patched. The v4.6.7 release notes enumerate three security-fix items:

  • Authentication bypass for some integrated accounts: accounts provisioned through LDAP, PAM or SSO could bypass two-factor authentication using any password.
  • Denial of service from pathological JSON-LD activities: processing specially problematic activity data could disrupt server availability.
  • Admin API access retained by disabled staff accounts: disabling a staff account did not remove its access to the admin API.

Those three items are not evidence of the exact four bugs named in the headline. Nor should they be assumed to describe every security fix in the other supported releases.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why server updates matter to users

Security fixes are applied to the server software by its administrator. Ordinary Mastodon users cannot install them through the app or their account settings. If an instance runs an outdated version, a user may have no direct way to fix that exposure; the practical step is to contact the operator or move to a better-maintained server.

A July 27, 2026 advisory offers an example of the kind of server-side risk a patch can address. Mastodon described an endpoint intended for instance administrators that checked permissions before returning statistics, but not before calculating them. Anonymous requests could therefore trigger expensive, long-running SQL queries and potentially exhaust server resources. The advisory lists patched versions 4.6.4, 4.5.14 and 4.4.21, plus 4.7.0-alpha.2 for the alpha branch. These are the advisory’s stated fixes for that issue—not a claim that the supported releases listed in September remained vulnerable. Mastodon’s statistics-endpoint advisory

Is Mastodon safe to use?

There is no reliable blanket yes or no. Mastodon’s maintainers publish fixes for flaws in the software, but they do not certify every independently run instance. Your experience and exposure also depend on whether the server operator keeps the software maintained and how that instance handles moderation, federation, privacy and account administration.

Mastodon 4.7, announced August 20, 2026, was described by the project as a technical release focused on compatibility, performance and bug fixes. One security-related change encrypts local users’ private keys used for ActivityPub authentication in the database, intended to reduce risk from leaks such as database backups or external database providers. The project says ordinary users do not need to understand those protocol details to use Mastodon. Mastodon 4.7 release announcement

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to assess a Mastodon instance

Before creating an account, look beyond the Mastodon name. Check the individual instance’s operator, policies and maintenance information; no instance ranking or safety certification is established by the sources cited here.

  • Operator and contact: Is it clear who runs the server, and does the site provide a way to contact them?
  • Software maintenance: Does the operator communicate about updates or otherwise show that the server is maintained?
  • Rules and moderation: Read the instance’s rules and understand its moderation and federation policies. These can differ from server to server.
  • Privacy and terms: Review the instance’s privacy practices and terms before sharing information or posting.

Mastodon GmbH’s terms effective August 31, 2026 apply to mastodon.social and mastodon.online—not to every server on the network. Independent instances set their own administrative rules. Mastodon’s July 31, 2026 terms announcement

Which Mastodon versions were supported?

Mastodon’s security policy, as reflected in the cited material, lists 4.7.0 and 4.6.0 as supported; 4.5.x support through February 20, 2027; and 4.4.x through December 17, 2026. Versions below 4.4 are listed as unsupported. Separately, the September 15, 2026 engineering update named 4.7.1, 4.6.7, 4.5.17 and 4.4.24 as the latest supported releases at that time. These are dated snapshots, not a guarantee of the current supported versions; operators should check the project’s policy and releases for the latest information. Mastodon security policy

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where to report a security problem

Mastodon distinguishes flaws in its distributed code from problems specific to one installation. Its security policy directs people to report code vulnerabilities privately through the project’s security process or by emailing security@joinmastodon.org, rather than disclosing them publicly before a fix. Installation-specific issues such as misconfiguration should be reported to that instance’s owner. Mastodon security policy

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.