Allocation of Resources Without Limits or Throttling in Mastodon - #VU139923
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in statistics endpoints when handling anonymous requests. A remote attacker can issue potentially expensive requests to cause a denial of service.
The affected endpoints check permissions before returning results, but not before computing them, which can trigger expensive long-running SQL queries.