CVEs we hold for Misskey-dev
Records whose assigning authority named Misskey-dev as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-47746Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacksmisskey-dev misskey
CVE-2026-46714Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilationmisskey-dev misskey
CVE-2026-46713Misskey: JSON-LD signature validation + compaction may lead to improper activity handlingmisskey-dev misskey
CVE-2026-46712Misskey: Lack of proper permission checks in Direct Messaging featuremisskey-dev misskey
CVE-2025-66482Misskey has a login rate limit bypass via spoofed X-Forwarded-For headermisskey-dev misskey
CVE-2025-25306Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notesmisskey-dev misskey
CVE-2025-24897Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributesmisskey-dev misskey
CVE-2024-52579Server-Side Request Forgery vulnerability in various APIs in Misskeymisskey-dev misskey
CVE-2024-49363Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskeymisskey-dev misskey
CVE-2024-32983Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activitiesmisskey-dev misskey
CVE-2024-25636Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accountsmisskey-dev misskey
CVE-2023-52139Misskey vulnerable to improper authorization when accessing with third-party applicationmisskey-dev misskey
CVE-2023-49079Misskey's missing signature validation allows arbitrary users to impersonate any remote user.misskey-dev misskey
CVE-2023-24811Cross site scripting (XSS) vulnerability using url preview in Misskeymisskey-dev misskey
CVE-2023-24810Cross site scripting (XSS) vulnerability using authentication callback in Misskeymisskey-dev misskey
35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.