CVE-2026-50129: fallo de gravedad alta en mastodon
Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.5%
probabilidad de explotación
0.5%top 62% de las CVE
explotación observada
noninguna fuente lo reporta
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed <math> nodes can result in a DoS of a whole server or targeted users services, depending on the type of action that includes the malformed nodes and the services interacting with it. This vulnerability is fixed in 4.5.11, 4.4.18, and 4.3.24.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
mastodon · mastodonCVEs relacionadas — mastodon
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-36460CRITICALMastodon vulnerable to arbitrary file creation through media attachmentsEPSS 40.1%CVE-2024-23832CRITICALMastodon Remote user impersonation and takeoverEPSS 2.5%CVE-2023-36461HIGHMastodon vulnerable to Denial of Service through slow HTTP responsesEPSS 1.3%CVE-2023-28853HIGHMastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databaseEPSS 1.3%CVE-2023-36459CRITICALMastodon vulnerable to Cross-site Scripting through oEmbed preview cardsEPSS 1.2%CVE-2026-72914HIGHMastodon: Exhausting data by an unauthenticated request to the admin retention APIEPSS 0.8%