The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9 | Patch |
Configurations
History
No history.
Information
Published : 2026-05-20 20:16
Updated : 2026-07-23 15:10
NVD link : CVE-2026-9137
Mitre link : CVE-2026-9137
CVE.ORG link : CVE-2026-9137
JSON object : View
Products Affected
misp-project
- misp
CWE
CWE-400
Uncontrolled Resource Consumption
