CVE-2026-50129
Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER
7.5
HIGH
CVSS 3.1
EPSS 0.26%
描述
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed <math> nodes can result in a DoS of a whole server or targeted users services, depending on the type of action that includes the malformed nodes and the services interacting with it. This vulnerability is fixed in 4.5.11, 4.4.18, and 4.3.24.
如何修補 CVE-2026-50129
要修補 CVE-2026-50129,請將受影響套件升級到下列已修補版本。
- —升級至 4.3.24 或更新版本
CVE-2026-50129 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4.3.24, >= 4.4.0, < 4.4.18, >= 4.5.0, < 4.5.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |