PT-2026-69983 · Mastodon · Mastodon
CVE-2026-72914
·
Published
2026-08-10
·
Updated
2026-08-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mastodon versions prior to 4.4.21
Mastodon versions prior to 4.5.14
Mastodon versions prior to 4.6.4
Mastodon versions prior to 4.7.0-beta.1
Description
Administrative statistics endpoints handled by
Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController perform authorization checks only after initiating resource-intensive calculations. Unauthenticated users can provide keys, start at, and end at parameters to trigger long-running SQL queries within Admin::Metrics::Measure, Admin::Metrics::Retention, and Admin::Metrics::Dimension::BaseDimension. Repeated requests of this nature can lead to the exhaustion of server resources.Recommendations
Update to version 4.4.21
Update to version 4.5.14
Update to version 4.6.4
Update to version 4.7.0-beta.1
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mastodon