CVE-2026-47746 debrief: Misskey social media platform vulnerable to timing attacks during JSON-LD signature validation and compaction process. The vulnerability allows fraudulent activities to be accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4. Defenders should prioritize verifying and applying the patch to prevent potential fraudulent activities. The vulne [truncated]
CVE-2026-46713 is a critical vulnerability in Misskey, an open-source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4. The vulnerability impacts the integrity of user interactions, allow [truncated]
CVE-2026-46712 is a vulnerability in Misskey, an open-source, federated social media platform. The issue allows unauthorized access to certain Direct Messages data points due to improper permission checks, affecting versions 2025.3.2 and later, prior to 2026.5.4. This vulnerability is independent of federation status and does not affect notes with 'specified' visibility. The issue has been fixed in version 2026.5.4.
CVE-2026-57575 is a Server-Side Request Forgery (SSRF) vulnerability in Misskey's URL preview functionality. The issue allows a remote attacker to cause the Misskey server to initiate HTTP requests to loopback, private, or link-local services due to missing network restrictions before establishing outbound connections. However, no sensitive internal data is believed to be transmitted back or exposed to th [truncated]
CVE-2026-57574 is a HIGH-severity vulnerability in Misskey's Time-based One-Time Password (TOTP) authentication. The issue allows the reuse of a single-use TOTP code within its valid time step if both credentials and the TOTP code are obtained concurrently. This could lead to unauthorized actions, potentially resulting in account takeover. The vulnerability is fixed in Misskey version 2026.6.0. The vulner [truncated]