Is Mastodon 3.0.2 patched?
Current stable (4.5.11): 100/100
3.0.2 has 13 open critical-or-high vulnerabilities. Run 4.3.22 or later to clear them. See what 4.3.22 fixes →
Summary iPlain-English security status for Mastodon 3.0.2, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Mastodon 3.0.2 is part of the 3.0 release line. 30 known vulnerabilities affect it. The minimum safe version is 4.3.22 — upgrade to it or later to clear the open critical/high issues. The latest supported Mastodon release is 4.5.11.
Known issues affecting 3.0.2
Exploited first, then by exploitation probability.
CVE-2022-0432 MEDIUM EPSS 4% → fixed in 3.5.0 CVE-2024-23832 CRITICAL EPSS 2% → fixed in 4.2.5 CVE-2022-24307 CRITICAL EPSS 1% → fixed in 3.4.6 CVE-2023-28853 HIGH EPSS 1% → fixed in 4.1.2 CVE-2023-36461 HIGH EPSS 1% → fixed in 4.1.3 CVE-2023-36459 CRITICAL EPSS 1% → fixed in 4.1.3 CVE-2022-2166 CRITICAL EPSS 1% → see advisory CVE-2022-46405 HIGH EPSS 1% → see advisory CVE-2022-31263 MEDIUM EPSS 1% → fixed in 3.5.0 CVE-2023-42451 HIGH EPSS 1% → fixed in 4.1.8 CVE-2023-36462 MEDIUM EPSS 1% → fixed in 4.1.3 CVE-2024-37903 HIGH EPSS 1% → fixed in 4.2.10 CVE-2026-33868 MEDIUM EPSS 1% → fixed in 4.5.8 CVE-2024-25623 HIGH EPSS 1% → fixed in 4.2.7 CVE-2026-23962 HIGH EPSS 0% → fixed in 4.5.5 CVE-2024-25618 MEDIUM EPSS 0% → fixed in 4.2.6 CVE-2026-23961 MEDIUM EPSS 0% → fixed in 4.5.5 CVE-2026-25540 MEDIUM EPSS 0% → fixed in 4.5.6 CVE-2024-34535 MEDIUM EPSS 0% → see advisory CVE-2024-25619 LOW EPSS 0% → fixed in 4.2.6Other Mastodon versions
Check another release line of Mastodon.
Frequently asked
Is Mastodon 3.0.2 patched?
Mastodon 3.0.2 is end-of-life and no longer receives security patches. Move to 4.5.11.
What version should I upgrade Mastodon 3.0.2 to?
Upgrade Mastodon 3.0.2 to at least 4.3.22 to clear its 13 open critical-or-high vulnerabilities.
What is the latest version of Mastodon?
The latest supported Mastodon release is 4.5.11.
Is Mastodon 3.0.2 still receiving security updates?
No — Mastodon 3.0.2 is on the 3.0 line, which reached end-of-life and no longer receives security updates. Upgrade to 4.5.11 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Mastodon's official advisory before you patch or upgrade — Mastodon official site ↗