The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9 | Patch |
Configurations
History
02 Jun 2026, 16:34
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Misp
Misp misp |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| References | () https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9 - Patch |
29 May 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. |
20 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-20 20:16
Updated : 2026-06-02 16:34
NVD link : CVE-2026-9137
Mitre link : CVE-2026-9137
CVE.ORG link : CVE-2026-9137
JSON object : View
Products Affected
misp
- misp
CWE
CWE-400
Uncontrolled Resource Consumption
