PT-2025-32007 · Mastodon · Mastodon

Renchap

·

Published

2025-08-05

·

Updated

2025-08-26

·

CVE-2025-54879

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mastodon versions 3.1.5 through 4.2.24 Mastodon versions 4.3.0 through 4.3.11 Mastodon versions 4.4.0 through 4.4.3
Description Mastodon’s rate-limiting system contains a configuration error where the email-based throttle for confirmation emails incorrectly checks the password reset path instead of the confirmation path. This effectively disables per-email limits for confirmation requests, allowing attackers to bypass rate limits by rotating IP addresses and send unlimited confirmation emails to any email address. Only a weak IP-based throttle (25 requests per 5 minutes) remains active. This enables denial-of-service attacks that can overwhelm mail queues and facilitate user harassment through confirmation email spam.
Recommendations Update to Mastodon version 4.2.24. Update to Mastodon version 4.3.11. Update to Mastodon version 4.4.3.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2025-54879
CVE-2025-54879
GHSA-84CH-6436-C7MG

Affected Products

Mastodon