CVE-2026-28432
EUVD-2026-1036710.03.2026, 07:43
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| misskey | misskey | 𝑥 < 2026.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration