CVE-2025-27157: Mastodon's rate-limits are missing on `/auth/setup`
Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on /auth/setup. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.2.16 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27157?
CVE-2025-27157 is considered a moderate severity vulnerability due to its potential for email abuse via crafted requests.
How do I fix CVE-2025-27157?
To fix CVE-2025-27157, update your Mastodon installation to version 4.2.16 or 4.3.4, where the missing rate limits have been implemented.
What are the affected versions for CVE-2025-27157?
CVE-2025-27157 affects Mastodon versions 4.2.0 up to 4.2.16 and 4.3.0 up to 4.3.4.
What impact does CVE-2025-27157 have on users?
CVE-2025-27157 allows attackers to send emails to arbitrary addresses, which could result in spam or phishing attempts.
Is there a workaround for CVE-2025-27157 if I cannot update?
Currently, there is no official workaround for CVE-2025-27157; updating to a patched version is the recommended mitigation.