2026-5-21 - Posting @tesaguri@fedibird.com -

06:03:21
2026-05-20 22:53:32 Posting Mastodon Engineering MastodonEngineering@mastodon.social

We just released Mastodon 4.5.10, 4.4.17, and 4.3.23.

These versions contain several medium and high severity security fixes.

Also, please note that this marks the final Mastodon v4.3 update, this branch is now unsupported. If you are still using it, please move to a newer version as soon as possible.

Full release notes and update instructions are available on the GitHub releases page.

github.com/mastodon/mastodon/r

Releases · mastodon/mastodon
06:03:34

Removal of integrity-protected JSON entries from signed activities · Advisory · mastodon/mastodon · GitHub
github.com/mastodon/mastodon/s

自分で報告しておいて言うのも何だけど、これパッチするの真面目かよ……(本当に自分で報告しておいて言うなである)

Removal of integrity-protected JSON entries from signed activities
06:04:27

ちなみに2年くらい前に報告したやつです(当時LD Signaturesを受け付けつつcompactionをしていない実装に対して報告して回っていたついでに報告した)。表示の上では“published May 20, 2026”とあるけど、アドバイザリの一覧画面では報告日時順らしき並びになっているな(4ページ目(<github.com/mastodon/mastodon/s>)の“published on May 30, 2024”な項目の間に挟まっている)

06:06:04

しかし同時にリリースされているアドバイザリの雰囲気からして、Mythosあたりも同じ重箱の隅が気になったとかだろうか(実際のところどうなのかは知りません)

06:18:52

2年前の私が“threat actor”という用語の用法を間違えていたのにしれっと修正が入っている……と思いきや、修正漏れがあって恥ずかしー(?)。CVE-2024-25623とかでも同様の誤りを含んでいて同様に修正されているけど、MisskeyのCVE-2024-25636とかでは修正されていないので生の黒歴史が見られます(?)。具体的には`s/threat actor/attacker/g`が正解。

「脅威アクター」を「攻撃者」の何かかっこいい表現くらいに思っていたんよ……

06:24:36
2026-05-21 02:35:44 Posting Fedify: ActivityPub server framework fedify@hollo.social
This account is not set to public on notestock.
06:25:02

Fedifyも対応しているのか。しかもこちらのアドバイザリは普通に詳細に踏み込んでいる(まあ、これをexploitするような人(AI?)ならパッチの意図も割と明らかだろうしね)。ならばもうある程度公に議論しても良いかな

06:28:53

個人的な意見としては`@included`とかは潰すには惜しい機能だと思っていて、私の対応案は別のものだったのだよね。具体的にはFedifyのアドバイザリでも言及のあるframingで所望の構造に固定するというもの……だったのだけど、いかんせんアドバイザリで言うところの“lose the root node”の問題の対応周りの処理がややこしかったので、まあ策としてあまり好まれそうにないよねという感じではあった

06:32:50

`@included`は、FedibirdのMastodon APIにおける`compact`表現やTwitter API v2の`includes`のような表現をActivity Streamsの`Collection`で実現したいのなら必要になる機能だと思っていて、一応Mastodonへの報告でもその話はしたのだけど、でも実際今のところは誰も使っていないしねーという話になり、まあそれはそうなのだけどさー……うーん……という気持ち

06:37:10

しかし、VCDIコンテクストで`proof`タームが`"@container": "@graph"`として定義されているわけだけど、LD SignatureとFEP-8b32 integrity proofを組み合わせた場合にcompact後に`@graph`が露出して検証に弾かれることになったりしないだろうか(公表前に気付くべきだったか、これ)

06:53:52

Security fixes 3: Electric boogalee (!1298) · Merge requests · TransFem.org / Sharkey · GitLab
activitypub.software/TransFem-

Sharkeyも対応しているのね

Security fixes 3: Electric boogalee (!1298) · Merge requests · TransFem.org / Sharkey · GitLab
06:54:24
06:55:17

何故リブログしないのかというと、これを見て察していただきたいのですけど(?):<sharkey.team/instance-info/fed>

06:59:48

github.com/misskey-dev/misskey

というか結局上流も対応したのか

Release 2026.5.4-beta.0 · misskey-dev/misskey
07:00:24

その節(CVE-2024-32983)ではframingが云々とかペダントリーを並べてすみませんでしたね(?)

07:02:35

単に`@included`やら`@graph`やらを拒否するのが事実上の標準になるの嫌だー(あなた`Content-Type`のときも同じようなことを言っていませんでした?(?))

07:10:37

いや、丁寧にframingとかやっていたなら真面目かもしれないけど、単に怪しい予約語を弾くだけの対応なら別に真面目でも何でもないか(失礼)

07:28:39

Give us today our daily LD Signatures spoofing vuln.
—Matthew 6:11

07:56:29
2026-05-21 07:01:34 Posting internetarchive internetarchive@mastodon.archive.org

Web history disappears when it can’t be preserved.

Today, many publishers are blocking the Wayback Machine from archiving parts of the public web, putting decades of digital history at risk.

Tell publishers: don’t block the Wayback Machine. Sign the petition ➡️ savethearchive.com/newsleaders/

Tell New York Times, The Atlantic, and USA Today to keep the crucial work of journalists in the Wayback Machine!
07:56:37

Save Save Page Now Now

07:56:57

08:03:54

savethearchive.com/newsleaders

引用されている記事のうちWiredのペイウォールはまあ良いとして、MarketplaceをWayback Machineから開くとスクリプトが壊れるのは皮肉っぽい

Tell New York Times, The Atlantic, and USA Today to keep the crucial work of journalists in the Wayback Machine!
08:04:59

(ペイウォールと言っても、これもJavaScript無効だと読めてしまうパターンっぽいけど)

08:18:48
2026-05-20 22:19:50 Posting 偽オム/hhvm hhvm@fedibird.com
This account is not set to public on notestock.
08:18:56

当初「ヒアリングは恫喝だ」という意見を見かけてちょっと先走りすぎではと思っていたけど、本当に聞き取りの場で「説明」をしつつ裏で売名呼ばわりするなんてことがあるのか……(今日のあるんだ)

12:12:12
2026-05-21 11:56:08 Posting :petthex_javasparrow:しゅいろ:petthex_javasparrow:(本物) syuilo@misskey.io
This account is not set to public on notestock.
12:13:15

JSON-LD signature validation + compaction may lead to improper activity handling · Advisory · misskey-dev/misskey · GitHub
github.com/misskey-dev/misskey

Finderのクレジットも入れてくれるの律儀だな。どうもー

JSON-LD signature validation + compaction may lead to improper activity handling
12:14:58

ただ、私CVE-2024-32983の時にこれも併せて報告しませんでしたっけ? ほら、compactionだけでなくframingもすべしーって20段落くらいかけて長々とまくし立てた報告文がそこに……(もう良いだろその話は。はい)

12:18:20

しかしこれを見るに、本当にClaudeの協力込みで再発見したパターンだったのか。ほえー

12:37:08

今回私は一切調整に関わっていないけど、複数実装に影響する脆弱性のリリースの調整は大変ですよねえ……という気持ち(蓋を開けてみたら思ったより多くの実装が関わっているようで驚いている)