Allocation of Resources Without Limits or Throttling in Mastodon - CVE-2025-54879
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the confirmation email throttle for the /auth/confirmation endpoint when handling confirmation email requests. A remote attacker can send repeated POST requests with the same email address to cause a denial of service.
By rotating IP addresses, requests can avoid the remaining IP-based throttle and target unconfirmed email addresses.