CVE-2026-23964 | Mastodon up to 4.3.17/4.4.11/4.5.4 Web Push Subscription Update Endpoint authorization (GHSA-f3q8-7vw3-69v4)
A vulnerability, which was classified as critical, was found in Mastodon up to 4.3.17/4.4.11/4.5.4. This impacts an unknown function of the component Web Push Subscription Update Endpoint. Executing a manipulation can lead to incorrect authorization.
The identification of this vulnerability is CVE-2026-23964. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.