Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0604

NIXPKGS-2026-0604
published 3 months, 2 weeks ago
updated 3 months, 2 weeks ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt added
    6 maintainers
    • @wegank
    • @Prince213
    • @OPNA2608
    • @fricklerhandwerk
    • @ethancedwards8
    • @eljamm
    maintainer.add
  • @mweinelt accepted
  • @mweinelt published on GitHub
HTTP signature verification can be bypassed

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether federation is enabled or disabled. This vulnerability is fixed in 2026.3.1.

Affected products

misskey
  • ==< 2026.3.1

Matching in nixpkgs

Package maintainers

Additional maintainers

https://github.com/misskey-dev/misskey/security/advisories/GHSA-grwc-c762-gcvp