CVE-2026-72916 | Mastodon up to 4.4.20/4.5.13/4.6.3 PrivateAddressCheck private_address_check.rb PrivateAddressCheck.private_address? infinite loop
A vulnerability labeled as critical has been found in Mastodon up to 4.4.20/4.5.13/4.6.3. The impacted element is the function PrivateAddressCheck.private_address? of the file app/lib/private_address_check.rb of the component PrivateAddressCheck. Executing a manipulation can lead to infinite loop.
This vulnerability is tracked as CVE-2026-72916. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More