Allocation of Resources Without Limits or Throttling in Mastodon - CVE-2026-23963
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in list names, filter names, and filter keywords when processing user-supplied values. A remote user can set arbitrarily long names or keywords to cause a denial of service.
A user can also render their own web interface unusable, including by unknowingly approving a malicious API client.