Insufficient Session Expiration in Mastodon - CVE-2024-25619
Published: February 14, 2024 / Updated: April 23, 2026
Mastodon
Mastodon
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficient session expiration in the streaming server when processing streaming connections associated with destroyed OAuth applications. A remote user can use access tokens that were not invalidated in streaming to disclose sensitive information.
Exploitation was only possible through a user-created application on the user's own account.