Vulnerability Details CVE-2025-27157
Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.5%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2025-27157
-
cpe:2.3:a:joinmastodon:mastodon:4.2.0
-
cpe:2.3:a:joinmastodon:mastodon:4.2.1
-
cpe:2.3:a:joinmastodon:mastodon:4.2.10
-
cpe:2.3:a:joinmastodon:mastodon:4.2.11
-
cpe:2.3:a:joinmastodon:mastodon:4.2.12
-
cpe:2.3:a:joinmastodon:mastodon:4.2.13
-
cpe:2.3:a:joinmastodon:mastodon:4.2.14
-
cpe:2.3:a:joinmastodon:mastodon:4.2.15
-
cpe:2.3:a:joinmastodon:mastodon:4.2.2
-
cpe:2.3:a:joinmastodon:mastodon:4.2.3
-
cpe:2.3:a:joinmastodon:mastodon:4.2.4
-
cpe:2.3:a:joinmastodon:mastodon:4.2.5
-
cpe:2.3:a:joinmastodon:mastodon:4.2.6
-
cpe:2.3:a:joinmastodon:mastodon:4.2.7
-
cpe:2.3:a:joinmastodon:mastodon:4.2.8
-
cpe:2.3:a:joinmastodon:mastodon:4.2.9
-
cpe:2.3:a:joinmastodon:mastodon:4.3.0
-
cpe:2.3:a:joinmastodon:mastodon:4.3.1
-
cpe:2.3:a:joinmastodon:mastodon:4.3.2
-
cpe:2.3:a:joinmastodon:mastodon:4.3.3