
Misskey/Sharkey "extremely severe" vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/09/7 These ActivityPub-based social network services (similar to Mastodon) have released updates CVE-2026-28431: Information disclosure CVE-2026-28432: Authentication bypass CVE-2026-28433: Authorization bypass
Post summary
Advisory announces updates for Misskey/Sharkey covering CVE‑2026‑28431 (info disclosure), CVE‑2026‑28432 (authentication bypass), and CVE‑2026‑28433 (authorization bypass).


