Improper Authorization in Mastodon - CVE-2026-33869
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to prevent a quote from being correctly processed on the server.
The vulnerability exists due to improper authorization handling in quote authorization when processing a quote before it has reached a server. A remote attacker can know of a quote in advance to prevent a quote from being correctly processed on the server.