
Misskey/Sharkey "extremely severe" vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/09/7 These ActivityPub-based social network services (similar to Mastodon) have released updates CVE-2026-28431: Information disclosure CVE-2026-28432: Authentication bypass CVE-2026-28433: Authorization bypass
Post summary
The post announces that Misskey/Sharkey have released patches for three critical CVEs, describing the vulnerability types but providing no PoC, exploit, or evidence of active exploitation.


