CVE-2026-50129: high-severity vulnerability in mastodon
Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed <math> nodes can result in a DoS of a whole server or targeted users services, depending on the type of action that includes the malformed nodes and the services interacting with it. This vulnerability is fixed in 4.5.11, 4.4.18, and 4.3.24.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
mastodon · mastodonRelated CVEs — mastodon
In the same product, most dangerous first.
CVE-2023-36460CRITICALMastodon vulnerable to arbitrary file creation through media attachmentsEPSS 40.1%CVE-2024-23832CRITICALMastodon Remote user impersonation and takeoverEPSS 2.5%CVE-2023-36461HIGHMastodon vulnerable to Denial of Service through slow HTTP responsesEPSS 1.3%CVE-2023-28853HIGHMastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databaseEPSS 1.3%CVE-2023-36459CRITICALMastodon vulnerable to Cross-site Scripting through oEmbed preview cardsEPSS 1.2%CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS 0.8%