CVE-2026-9137

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-20 20:16

Updated : 2026-07-23 15:10


NVD link : CVE-2026-9137

Mitre link : CVE-2026-9137

CVE.ORG link : CVE-2026-9137


JSON object : View

Products Affected

misp-project

  • misp
CWE
CWE-400

Uncontrolled Resource Consumption