Wowzers, that Mastodon CVE recently was quite something:
β’ You can inject a post that is attributed to any remote user
β’ You can overwrite the server's copy of any remote user
β’ You can rekey the server's copy of any remote user, by just listing another key
The full technical write up is worth a read: https://arcanican.is/excerpts/cve-2024-23832/discovery.htm