CVE-2026-47746: Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Misskeyto a version that resolves this vulnerability.Fixed in 2026.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47746?
The severity of CVE-2026-47746 is rated at 51.
How do I fix CVE-2026-47746?
To fix CVE-2026-47746, upgrade Misskey to version 2026.5.4 or later.
What versions of Misskey are affected by CVE-2026-47746?
CVE-2026-47746 affects Misskey versions from 12.37.0 up to, but not including, 2026.5.4.
What type of attack is CVE-2026-47746 susceptible to?
CVE-2026-47746 is vulnerable to timing attacks during JSON-LD signature validation and the compaction process.
What component of Misskey does CVE-2026-47746 impact?
CVE-2026-47746 impacts the JSON-LD signature validation and compaction processes in Misskey.