In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
{ "cpes": [ "cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*" ], "severity": "Medium" }