Misskey
cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*
- < 2026.3.1
A vulnerability exists in Misskey servers prior to version 2026.3.1 that allows for bypassing HTTP signature verification. This issue, while related to federation, impacts all servers regardless of their federation settings. The vulnerability has been addressed in version 2026.3.1.
Exploitation of this vulnerability allows for the bypass of HTTP signature verification, which could lead to unauthorized actions being performed on behalf of a user or server.
Users are advised to update to Misskey version 2026.3.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.