Critical severity9.8NVD Advisory· Published Nov 16, 2022· Updated Jun 17, 2026
CVE-2022-2166
CVE-2022-2166
Description
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*range: <=3.5.5
- cpe:2.3:a:joinmastodon:mastodon:4.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:joinmastodon:mastodon:4.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:joinmastodon:mastodon:4.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:joinmastodon:mastodon:4.0.0:rc4:*:*:*:*:*:*
- (no CPE)range: <4.0.0
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/mastodon/mastodon/commit/21fd25a269cca742af431f0d13299e139f267346nvdPatchThird Party Advisory
- huntr.dev/bounties/2f96f990-01c2-44ea-ae47-58bdb3aa455bnvdThird Party Advisory
News mentions
0No linked articles in our index yet.