CVE-2023-36461

    Dashboard / Vulnerabilities / CVE-2023-36461

    CVE-2023-36461

    Published: 6 Jul 2023Last Modified: 12 Aug 2026

    Summary: Mastodon vulnerable to Denial of Service through slow HTTP responses

    Details: Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks. This vulnerability can be used to keep all Mastodon workers busy for an extended duration of time, leading to the server becoming unresponsive. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v3.5.8
    v3.5.7
    v3.5.6
    v3.5.5
    v3.5.4
    v3.5.3
    v3.5.2
    v3.5.1
    v3.5.0
    v3.5.0rc3
    v3.5.0rc2
    v3.5.0rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-36461 | CVE-DB