CVE-2026-46714: Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation
Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Misskey web clientto a version that resolves this vulnerability.Fixed in 2026.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46714?
CVE-2026-46714 has a risk rating of 26, indicating a significant impact on the system's performance.
How do I fix CVE-2026-46714?
You can fix CVE-2026-46714 by updating Misskey to version 2026.5.4 or later.
What versions of Misskey are affected by CVE-2026-46714?
CVE-2026-46714 affects Misskey versions 8.63.0 and later but prior to 2026.5.4.
What type of vulnerability is CVE-2026-46714?
CVE-2026-46714 is a Denial of Service vulnerability caused by uncontrolled recursion in theme compilation.
What symptoms might indicate CVE-2026-46714 is being exploited?
Symptoms of CVE-2026-46714 exploitation include significant slowdowns or crashes of the Misskey web client when applying malformed themes.