What is CVE-2026-59825?
CVE-2026-59825 is a critical vulnerability in Mastodon, a free open-source social network server, where using 'LDAP_TLS_NO_VERIFY=true' for LDAP authentication disables SSL/TLS verification. This affects versions prior to 4.4.1, and from 4.4.19 to 4.5.12. Users are advised to update their Mastodon servers to the patched version to mitigate the risk.
Azərbaycanca: CVE-2026-59825, açıq mənbəli Mastodon sosial şəbəkə serverində LDAP autentifikasiyası zamanı 'LDAP_TLS_NO_VERIFY=true' parametri istifadə edildikdə, SSL/TLS doğrulamasını deaktiv edən təhlükəsizlik zəifliyidir. Bu, 4.4.1-dən əvvəlki, həmçinin 4.4.19 və 4.5.0 ilə 4.5.12 arası versiyalara təsir edir. İstifadəçilərə Mastodon serverini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
How can I check if my Mastodon server is affected by CVE-2026-59825?
Your Mastodon server is affected if it runs versions prior to 4.4.1, up to 4.4.19, or from 4.5.0 to 4.5.12.
What causes the CVE-2026-59825 vulnerability in LDAP authentication?
The vulnerability occurs because using the 'LDAP_TLS_NO_VERIFY=true' configuration parameter for LDAP authentication disables SSL/TLS verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.