Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| Vendors & Products |
Misskey
Misskey misskey |
Mon, 09 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1. | |
| Title | HTTP signature verification can be bypassed | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-09T21:19:43.220Z
Updated: 2026-03-10T14:45:12.846Z
Reserved: 2026-02-27T15:54:05.137Z
Link: CVE-2026-28432
No data.
Status : Received
Published: 2026-03-10T07:43:35.770
Modified: 2026-03-10T07:43:35.770
Link: CVE-2026-28432
No data.
ReportizFlow