BIT-mastodon-2026-59825

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mastodon/BIT-mastodon-2026-59825.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mastodon-2026-59825
Aliases
Published
2026-08-24T05:45:37Z
Modified
2026-08-24T08:25:58Z
Summary
Mastodon: Unwanted deactivation of SSL/TLS certificate verification
Details

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.

Database specific
{
    "cpes": [
        "cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / mastodon

Package

Name
mastodon
Purl
pkg:bitnami/mastodon

Severity

  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.19
Introduced
4.5.0
Fixed
4.5.12

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/mastodon/BIT-mastodon-2026-59825.json"