For those who like to read CVE and security advisories, here are the ones related to today's Mastodon patches.
https://github.com/mastodon/mastodon/security/advisories/GHSA-55j9-c3mp-6fcq https://github.com/mastodon/mastodon/security/advisories/GHSA-9pxv-6qvf-pjwc https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm https://github.com/mastodon/mastodon/security/advisories/GHSA-ccm4-vgcc-73hp
These were the result of a security audit done by Cure53, and funded by Mozilla.