#VU126978 Allocation of Resources Without Limits or Throttling in Mastodon - CVE-2025-27157
Published: February 27, 2025 / Updated: April 23, 2026
Mastodon
Mastodon
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the sign-up email verification feature when handling requests to change or re-request email verification during the sign-up flow. A remote attacker can send crafted requests to cause a denial of service.
The issue can be abused to send email messages to arbitrary addresses.