Improper Authorization in Mastodon - CVE-2026-33869
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to prevent a quote from being correctly processed on the server.
The vulnerability exists due to improper authorization handling in quote authorization when processing a quote before it has reached a server. A remote attacker can know of a quote in advance to prevent a quote from being correctly processed on the server.