CVE-2026-28432

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*

History

13 Mar 2026, 17:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*
References () https://github.com/misskey-dev/misskey/security/advisories/GHSA-grwc-c762-gcvp - () https://github.com/misskey-dev/misskey/security/advisories/GHSA-grwc-c762-gcvp - Vendor Advisory
Summary
  • (es) Misskey es una plataforma de redes sociales de código abierto y federada. Todos los servidores Misskey anteriores a 2026.3.1 contienen una vulnerabilidad que permite eludir la verificación de firmas HTTP. Aunque esta es una vulnerabilidad relacionada con la federación, afecta a todos los servidores independientemente de si la federación está habilitada o deshabilitada. Esta vulnerabilidad está corregida en 2026.3.1.
First Time Misskey misskey
Misskey

10 Mar 2026, 07:43

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 07:43

Updated : 2026-03-13 17:18


NVD link : CVE-2026-28432

Mitre link : CVE-2026-28432

CVE.ORG link : CVE-2026-28432


JSON object : View

Products Affected

misskey

  • misskey
CWE
CWE-347

Improper Verification of Cryptographic Signature