Open Source Security mailing list@oss_securityPatch
Misskey/Sharkey released updates to remediate three CVEs—information disclosure, authentication bypass, and authorization bypass—without any PoC, exploit, or active exploitation reported.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post simply lists CVE identifiers and a link to a vulnerability database without providing additional technical or exploit-related details.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text simply lists the CVE identifier and links to a vulnerability details page without providing additional technical or exploit information.
0day Signal@0dayPublishingDisclosure
A new CVE-2026-28431 affecting Misskey is disclosed, featuring unauthenticated data exfiltration due to broken authorization checks; no PoC, exploit tool, patch, or active exploitation evidence is included.
CVE@CVEnewDisclosure
The text announces CVE-2026-28431 affecting Misskey servers from v8.45.0 up to but excluding 2026.3.1, without providing technical details, exploit code, or mitigation information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet references two CVE identifiers and provides links to a vulnerability details page and alert service, but gives no specific technical information, PoC, patch details, or evidence of exploitation.