Uncontrolled Recursion in Misskey - CVE-2024-49363
Published: December 18, 2024 / Updated: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in FileServerService.prototype.proxyHandler when processing nested proxy requests with a malicious redirect loop. A remote attacker can send a maliciously crafted note to cause a denial of service.
Instances with an external media proxy configured are also affected.