Input validation error in Mastodon - CVE-2026-23962
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in poll handling for remote posts when processing remote posts containing an excessive number of poll options. A remote attacker can create a remote post with a very large number of poll options to cause a denial of service.
The issue can cause disproportionate resource consumption in both Mastodon servers and clients.