Junglewise Threat Intelligence

CVE-2026-59825: Mastodon LDAP authentication global TLS verification bypass

CVE-2026-59825 · Severity: high · CVSS 7.4 · Published 2026-08-18

Technologies: Mastodon. Vendors: Mastodon.

Executive brief

Mastodon, a popular open-source social network server, contains a configuration error in its LDAP authentication module that disables TLS certificate verification globally across all web server requests when LDAP_TLS_NO_VERIFY is enabled. This allows attackers performing man-in-the-middle attacks to intercept encrypted connections to external services without detection, compromising the confidentiality of sensitive data in transit.

Technical details

The vulnerability exists in app/models/concerns/user/ldap_authenticable.rb, where LDAP authentication with LDAP_TLS_NO_VERIFY=true mutates the global OpenSSL::SSL::SSLContext::DEFAULT_PARAMS, disabling certificate verification for all subsequent TLS/SSL connections in puma web processes. This is a configuration validation issue: the code attempts to disable verification only for LDAP connections but inadvertently affects all outbound HTTPS requests from the web server. The vulnerability requires LDAP authentication to be configured and explicitly enabled via the LDAP_TLS_NO_VERIFY environment variable. An attacker with network position for MITM attacks can intercept connections to any external service called by Mastodon. The fix involves properly scoping certificate verification settings to only the LDAP context rather than mutating global OpenSSL defaults.

Affected products

  • Mastodon Mastodon prior to 4.4.19 and 4.5.0 to 4.5.12

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in versions 4.4.19 and 4.5.12

References

Related threats