CVE-2026-59825

Mastodon: Unwanted deactivation of SSL/TLS certificate verification

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.


We have discovered 711 live websites that are affected by CVE-2026-59825.

Run a Free Instant Scan




Affected Software

Product  Mastodon
Category Message Boards
Vulnerable Domains711 live websites (52% of Mastodon install base)
Vulnerable Versions
  • from 0 through 4.4.19
  • from 4.5 through 4.5.12
Vulnerable Versions Count66 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-295 Improper Certificate Validation



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Website Distribution by Country

Number of websites using CVE-2026-59825
United States215 websites



Germany151 websites
France136 websites
Japan62 websites
Singapore33 websites
GB16 websites
Canada12 websites
Austria8 websites
Netherlands7 websites

Website Distribution by TLD

Number of websites using CVE-2026-59825
.com97 websites
.net85 websites
.org48 websites
.de20 websites
.jp19 websites
.io12 websites
.fr11 websites
.info10 websites
.eu10 websites
.co7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59825

Top websites that are affected by CVE-2026-59825. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Germany***
********.xyz Germany**,***
*****.net United States***,***
**********.town United States***,***
******.*****.lv Germany***,***
*********.com Germany***,***
**********.online United States***,***
****.wales GB***,***
******.space Germany***,***
******.social Germany***,***
See full domain list

FAQ

CVE-2026-59825 is Improper Certificate Validation in Mastodon
A total of 711 websites have been identified as vulnerable to CVE-2026-59825, based on global website indexing conducted by WebTechSurvey.
The Mastodon is affected by the CVE-2026-59825 vulnerability.
Mastodon versions up to 4.5.12 are vulnerable to CVE-2026-59825.
CVE-2026-59825 is resolved in version 4.5.12 of Mastodon.