CVE-2026-47746
Received Received - Intake

Timing Attack in Misskey Leading to TOCTOU Vulnerability

Vulnerability report for CVE-2026-47746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: GitHub, Inc.

Description

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misskey misskey From 12.37.0 (inc) to 2026.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Misskey versions 12.37.0 to 2026.5.3 have a timing attack vulnerability during JSON-LD signature validation and compaction. The issue occurs because the JSON-LD parsing context is not shared between signature verification and later processing steps. This creates a time-of-check to time-of-use flaw, allowing attackers to bypass validation and inject fraudulent data that the system accepts as legitimate.

Impact Analysis

An attacker could exploit this to have fraudulent activities accepted as valid on your Misskey instance. This could lead to unauthorized content being posted, manipulated data being trusted, or integrity loss in federated communications. The impact includes potential misinformation spread, compromised user trust, and unauthorized actions performed under false credentials.

Compliance Impact

This vulnerability could violate integrity requirements in GDPR and HIPAA by allowing unauthorized data modifications or fraudulent activities. GDPR requires data integrity (Article 5), and HIPAA mandates integrity controls for protected health information. Exploitation could lead to unauthorized data changes, compromising compliance and potentially resulting in legal penalties or data breach notifications.

Mitigation Strategies

Upgrade Misskey to version 2026.5.4 or later to address the timing attack vulnerability in JSON-LD processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart