CVE-2026-28432Disclosure(misskey / misskey)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch misskey misskey systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • misskey

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
misskey

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-09: 3Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 203-09
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    Misskey/Sharkey "extremely severe" vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/09/7 These ActivityPub-based social network services (similar to Mastodon) have released updates CVE-2026-28431: Information disclosure CVE-2026-28432: Authentication bypass CVE-2026-28433: Authorization bypass

    Post summary

    The post announces that Misskey/Sharkey have released patches for three critical CVEs, describing the vulnerability types but providing no PoC, exploit, or evidence of active exploitation.

    00010719
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28432 Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verific… https://www.cve.org/CVERecord?id=CVE-2026-28432

    Post summary

    The post discloses CVE-2026-28432 for Misskey servers before version 2026.3.1, detailing a bypass of HTTP signature verification, but it does not provide a PoC, exploit, active exploitation evidence, patch, or debunking claim.

    0000097
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28432 CVE-2026-28431+more https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28432 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post simply lists two CVE identifiers and links to a generic vulnerability details page without providing further context or actionable information.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmisskeymisskey---

Explore more