CVE-2026-50129Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed <math> nodes can result in a DoS of a whole server or targeted users services, depending on the type of action that includes the malformed nodes and the services interacting with it. This vulnerability is fixed in 4.5.11, 4.4.18, and 4.3.24.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-24: 2Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 206-24
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50129 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerab… https://www.cve.org/CVERecord?id=CVE-2026-50129 ----- Traducción: CVE-2026-50129 Mas… http://infoflow.cloud`

    Post summary

    The tweet announces a DoS vulnerability (CVE-2026-50129) in Mastodon affecting versions before 4.5.11, 4.4.18, and 4.3.24, triggered by an uncaught exception, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    0000042
    88 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-50129 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerab… https://www.cve.org/CVERecord?id=CVE-2026-50129

    Post summary

    CVE‑2026‑50129 is a denial‑of‑service flaw in Mastodon before versions 4.5.11, 4.4.18, and 4.3.24; updating to those releases mitigates the issue.

    000001.1K
    57.7K followersView on X

Explore more