Denial of Service Vulnerability in Mastodon Social Network Server
CVE-2026-50129

7.5HIGH

Key Information:

Vendor

Mastodon

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-50129?

A vulnerability in the Mastodon social network server allows for denial of service attacks due to improper exception handling in the math sanitizer. Malformed nodes can trigger an uncaught exception, potentially leading to service disruption for the entire server or impacting specific users. This vulnerability has been addressed in versions 4.5.11, 4.4.18, and 4.3.24, ensuring better handling of input to prevent service interruptions.

Affected Version(s)

mastodon >= 4.5.0-beta.1, < 4.5.11 < 4.5.0-beta.1, 4.5.11

mastodon >= 4.4.0-beta.1, < 4.4.18 < 4.4.0-beta.1, 4.4.18

mastodon < 4.3.24 < 4.3.24

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.