In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
{ "cpes": [ "cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*" ], "severity": "Medium" }
"https://github.com/bitnami/vulndb/tree/main/data/mastodon/BIT-mastodon-2024-34535.json"