PT-2026-69983 · Mastodon · Mastodon

CVE-2026-72914

·

Published

2026-08-10

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mastodon versions prior to 4.4.21 Mastodon versions prior to 4.5.14 Mastodon versions prior to 4.6.4 Mastodon versions prior to 4.7.0-beta.1
Description Administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController perform authorization checks only after initiating resource-intensive calculations. Unauthenticated users can provide keys, start at, and end at parameters to trigger long-running SQL queries within Admin::Metrics::Measure, Admin::Metrics::Retention, and Admin::Metrics::Dimension::BaseDimension. Repeated requests of this nature can lead to the exhaustion of server resources.
Recommendations Update to version 4.4.21 Update to version 4.5.14 Update to version 4.6.4 Update to version 4.7.0-beta.1

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2026-72914
CVE-2026-72914
GHSA-7JVV-FHMG-WPFW

Affected Products

Mastodon