Observable discrepancy in Mastodon - CVE-2025-67500
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to inconsistent error handling in status lookup handling when processing requests with a non-English Accept-Language header. A remote attacker can send a request for a known status identifier to disclose sensitive information.
The issue only allows confirmation of whether a private status exists and cannot be used to learn its contents or other properties.