CVE-2023-49952: Joinmastodon Mastodon

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

Affected products

  • Joinmastodon Mastodon: from 4.1.0, before 4.1.17 (fixed in 4.1.17); from 4.2.0, before 4.2.9 (fixed in 4.2.9)

Published 2024-11-18. Last modified 2026-06-17.