Mastodon's rate-limits are missing on `/auth/setup`
CVE-2025-27157

5.3MEDIUM

Key Information:

Vendor
Mastodon
Status
Mastodon
Vendor
CVE Published:
27 February 2025

Summary

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on /auth/setup. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.

Affected Version(s)

mastodon >= 4.2.0, < 4.2.16 < 4.2.0, 4.2.16

mastodon >= 4.3.0, < 4.3.4 < 4.3.0, 4.3.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.