Summary
All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled.
Workaround
There is no known workaround for this vulnerability.
Notes
We are intentionally limiting information at this time to protect servers that have not been patched yet. We have also fixed another critical vulnerability in 2026.3.1, so please update to the latest version of Misskey immediately.
Summary
All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled.
Workaround
There is no known workaround for this vulnerability.
Notes
We are intentionally limiting information at this time to protect servers that have not been patched yet. We have also fixed another critical vulnerability in 2026.3.1, so please update to the latest version of Misskey immediately.