CVE-2026-33869: Mastodon has a denial of service for quote authorization
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected because they do not support quotes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33869?
CVE-2026-33869 has been classified as a denial of service vulnerability that can disrupt service availability.
How do I fix CVE-2026-33869?
To fix CVE-2026-33869, upgrade to Mastodon versions 4.5.8 or 4.4.15 or later.
Which versions of Mastodon are affected by CVE-2026-33869?
CVE-2026-33869 affects Mastodon versions 4.5.x prior to 4.5.8 and 4.4.x prior to 4.4.15.
What type of attack does CVE-2026-33869 describe?
CVE-2026-33869 describes a denial of service attack that can prevent quote authorizations.
Is CVE-2026-33869 related to a specific feature in Mastodon?
Yes, CVE-2026-33869 specifically relates to quote authorization features within Mastodon.