Improper Verification of Cryptographic Signature in Misskey - CVE-2026-28432
Published: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass HTTP signature verification.
The vulnerability exists due to improper verification of cryptographic signature in HTTP signature verification when handling federation-related HTTP signatures. A remote attacker can send a specially crafted signed request to bypass HTTP signature verification.
The issue affects all servers regardless of whether federation is enabled or disabled.